Oracle Web Services Manager unspecified | CVE-2022-21497
NAME
Oracle Web Services Manager unspecified
- Platforms Affected:
Oracle Web Services 12.2.1.3.0
Oracle Web Services 12.2.1.4.0 - Risk Level:
8.1 - Exploitability:
Unproven - Consequences:
Other
DESCRIPTION
An unspecified vulnerability in Oracle Web Services Manager related to the Web Services Security component could allow an unauthenticated attacker to cause high confidentiality impact, high integrity impact, and no availability impact.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: None
- Remediation Level: Official Fix
MITIGATION
Refer to Oracle Critical Patch Update Advisory – April 2022 for patch, upgrade or suggested workaround information. See References.
- Reference Link:
https://www.oracle.com/security-alerts/cpuapr2022.html - Reference Link:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21497
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.