VYPR
High severity7.2NVD Advisory· Published Jul 21, 2021· Updated Jun 17, 2026

CVE-2021-2328

CVE-2021-2328

Description

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Alter Any Table privilege with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Affected products

6
  • cpe:2.3:a:oracle:text:12.1.0.2:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:oracle:text:12.1.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:text:12.2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:oracle:text:19c:*:*:*:*:*:*:*
    • (no CPE)range: 12.1.0.2, 12.2.0.1, 19c
  • Range: 12.1.0.2, 12.2.0.1, 19c
  • Oracle Corporation/Textv5
    Range: 12.1.0.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.