HTTP: Oracle OSS Support Tools Diagnostic Assistant External Entity Injection

This signature detects attempts to exploit a known vulnerability against Oracle. A successful attack can lead to sensitive information disclosure.

Extended Description

Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant). The supported version that is affected is Prior to 2.12.41. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise OSS Support Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all OSS Support Tools accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).

Affected Products

Oracle oss_support_tools

Short Name
HTTP:ORACLE:OSS-SUPPORT-XXE-INJ
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Assistant CVE-2021-2303 Diagnostic Entity External Injection OSS Oracle Support Tools
Release Date
09/30/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3423
False Positive
Unknown
Vendors

Oracle

CVSS Score

4.0

Found a potential security threat?