CVE-2021-2480
Last modified
CVE-2021-2480 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 11.1.1.9.0. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 11.1.1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Http Server | 11.1.1.9.0 |
References
- https://www.oracle.com/security-alerts/cpuoct2021.htmlVendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-2480?
How severe is CVE-2021-2480?
How do I fix CVE-2021-2480?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-24794The Connections Business Directory WordPress plugin before 1…4.8
- CVE-2021-24795The Filter Portfolio Gallery WordPress plugin through 1.5 is…6.5
- CVE-2021-24796The My Tickets WordPress plugin before 1.8.31 does not prope…6.1
- CVE-2021-24797The Tickera WordPress plugin before 3.4.8.3 does not properl…6.1
- CVE-2021-24798The WP Header Images WordPress plugin before 2.0.1 does not …6.1
- CVE-2021-24799The Far Future Expiry Header WordPress plugin before 1.5 doe…4.3
- CVE-2021-24800The DW Question & Answer Pro WordPress plugin through 1.3.4 …4.3
- CVE-2021-24801The WP Survey Plus WordPress plugin through 1.0 does not hav…4.3
- CVE-2021-24802The Colorful Categories WordPress plugin before 2.0.15 does …6.5
- CVE-2021-24803The Core Tweaks WP Setup WordPress plugin through 4.1 allows…8.8
- CVE-2021-24804The Simple JWT Login WordPress plugin before 3.2.1 does not …8.8
- CVE-2021-24805The DW Question & Answer Pro WordPress plugin through 1.3.4 …4.3
Are you affected by CVE-2021-2480?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
