A vulnerability marked as critical has been reported in Oracle Communications Cloud Native Core Policy 1.15.0. This affects an unknown function of the component Policy. This manipulation causes improper input validation. This vulnerability is tracked as CVE-2021-3572. The attack is possible to be carried out remotely. No exploit exists. It is... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2021-3572 | Oracle Communications Cloud Native Core Policy 1.15.0 input validation (Nessus ID 353178)
A vulnerability marked as critical has been reported in Oracle Communications Cloud Native Core Policy 1.15.0. This affects an unknown function of the…
Cyber Threat Intelligence & Forensik
Bedrohungsgraph · ATT&CK-Mapping · Exploit-Belege
IoC Intelligence
1 Indikatoren · Defanged · STIX 2.1
CVE-2021-3572
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle
PoC · Ausnutzung · Patch-Stufen
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Upstream-Patch-Referenz vorhanden (Commit-/Advisory-Link)
Exploit Weaponization & PoC Radar
Nur belegte Faktoren · kein Score-Theater
Exploit-DB
Kein EDB-EintragInteraktion
Interaktion nötigAuthentifizierung
ErforderlichÖffentliche PoC-Quellen:GitHub PoC: frenzymadness/CVE-2021-3572
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
BSI-Warnung (Deutschland)CVE-2021-3572
Splunk Splunk Enterprise: Mehrere Schwachstellen30.08.2023Xerox FreeFlow Print Server: Mehrere Schwachstellen21.06.2022Xerox FreeFlow Print Server: Mehrere Schwachstellen ermöglichen Ausführen von beliebigem Programmcode mit Administratorrechten14.06.2022
Advisory Radar
Offizielles Hersteller-Update verfügbar
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Red Hat Security Bulletin Verifiziertredhat.com
-
Oracle Critical Patch Update (CPU) Verifiziertoracle.com
-
Oracle Critical Patch Update (CPU) Verifiziertoracle.com
-
Web Referencesecurity.netapp.com