← Vulnerability feed

Vulnerability record · CVE-2021-2351 · published 21 July 2021

CVE-2021-2351: Oracle advanced networking option broken cryptographic algorithm vulnerability

Oracle · Advanced Networking Option

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

8.3 CVSS 3.1 High EPSS 2.4% · top 16.4% CWE-327 · Broken cryptographic algorithmCWE-384 · CWE-384
8.3CVSS 3.1 base score, v2 5.1
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
111Affected product versions listed by NVD
20References, 8 tagged exploit
25 Aug 2026Last modified by NVD

Description

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected products

111 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/165255/Oracle-Database-Protection-Mechanism-Bypass.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/165258/Oracle-Database-Weak-NNE-Integrity-Key-Derivation.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2021/Dec/19 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2021/Dec/20 ExploitMailing ListThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html PatchVendor Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchVendor Advisory
https://www.oracle.com/security-alerts/cpujan2023.html Vendor Advisory
https://www.oracle.com/security-alerts/cpujul2021.html PatchVendor Advisory
https://www.oracle.com/security-alerts/cpujul2022.html Vendor Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchVendor Advisory
http://packetstormsecurity.com/files/165255/Oracle-Database-Protection-Mechanism-Bypass.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/165258/Oracle-Database-Weak-NNE-Integrity-Key-Derivation.html ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2021/Dec/19 ExploitMailing ListThird Party Advisory
http://seclists.org/fulldisclosure/2021/Dec/20 ExploitMailing ListThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html PatchVendor Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchVendor Advisory
https://www.oracle.com/security-alerts/cpujan2023.html Vendor Advisory
https://www.oracle.com/security-alerts/cpujul2021.html PatchVendor Advisory
https://www.oracle.com/security-alerts/cpujul2022.html Vendor Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchVendor Advisory

Track CVE-2021-2351 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2019-2725Oracle WebLogic Server Web Services deserialization RCEOracle WebLogic Server's Web Services subcomponent contains an injection flaw (CWE-74) that allows unauthenticated remote code execution over HTTP. I…KEVEPSS 100%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed8.8CVE-2024-20953Oracle Agile PLM Export deserialization allows takeoverOracle Agile Product Lifecycle Management 9.3.6 contains a deserialization flaw in the Export component. A low-privileged attacker with network acces…KEVEPSS 3.9%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed7.5CVE-2024-21287Oracle Agile PLM Framework incorrect authorization exposes dataOracle Agile PLM Framework 9.3.6 contains an incorrect authorization flaw in the Software Development Kit / Process Extension component. An unauthent…KEVEPSS 1.7%analysed9.9CVE-2025-21556Oracle agile product lifecycle management incorrect authorization vulnerabilityVulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is…EPSS 0.64%9.8CVE-2026-71040Oracle agile product lifecycle management improper access control vulnerabilityVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily e…EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2021-2351), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.