Risk Scores
CVSS v2.0
4
EPSS Score
0.75%
73.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corporation | Database - Enterprise Edition | 12.1.0.2, 12.2.0.1, 19c |
| oracle | database_server | 12.1.0.2, 12.2.0.1, 19c |
Timeline
- Oct 20, 2021 CVE Published
- Oct 21, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 6, 2022 EPSS Score
- Jul 27, 2022 EPSS Score
- Nov 16, 2022 EPSS Score
- Jan 3, 2023 PoC Published
- Jan 5, 2023 PoC Published
- Jan 10, 2023 EPSS Score
- May 2, 2023 EPSS Score
References
- https://www.oracle.com/security-alerts/cpuoct2021verbose.html#DB advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html url
- https://databasesecurityninja.wordpress.com/2022/06/11/cve-2021-35576-bypassing-unified-audit-policy/ url
- http://packetstormsecurity.com/files/170354/Oracle-Unified-Audit-Policy-Bypass.html url
- http://packetstormsecurity.com/files/170373/Oracle-Database-Vault-Metadata-Exposure.html url
- https://nvd.nist.gov/vuln/detail/CVE-2021-35576 advisory
- https://databasesecurityninja.wordpress.com/2022/06/11/cve-2021-35576-bypassing-unified-audit-policy url