
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-2351 is a vulnerability in the Advanced Networking Option component of Oracle Database Server affecting versions 12.1.0.2, 12.2.0.1, and 19c. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via Oracle Net to compromise Advanced Networking Option. The vulnerability was discovered by Moritz Bechler of SySS GmbH and was disclosed to Oracle on March 17, 2021, with patches released in July 2021 (Oracle CPU Jul2021).
The vulnerability exists in Oracle's Native Network Encryption (NNE) protocol implementation. The issue stems from insecure fallback behavior that allows a man-in-the-middle attacker to bypass NNE's protection against man-in-the-middle attacks and hijack authenticated connections. The vulnerability received a CVSS 3.1 Base Score of 8.3 (High) with the vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H (NVD, Oracle CPU Jul2021).
Successful exploitation of this vulnerability can result in complete takeover of the Advanced Networking Option component. While the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. The attack requires human interaction from a person other than the attacker (NVD).
The vulnerability is difficult to exploit but can be attacked remotely without authentication. The attack involves performing a man-in-the-middle attack against the initial Diffie-Hellman key exchange during NNE negotiation. For JDBC Thin clients, this allows direct observation and manipulation of application level traffic. Other clients are also vulnerable due to key fallback behavior on the server side (FullDisclosure).
Oracle released patches in the July 2021 Critical Patch Update to address this vulnerability. The update introduces Native Network Encryption changes to prevent the use of weaker ciphers. Customers should review 'Changes in Native Network Encryption with the July 2021 Critical Patch Update' (Doc ID 2791571.1). Alternative mitigations include enforcing secured protocol versions by setting SQLNET.ALLOW_WEAK_CRYPTO_CLIENTS=FALSE (server-side) and SQLNET.ALLOW_WEAK_CRYPTO=FALSE (client-side), or using TLS-based transport security instead of Native Network Encryption (FullDisclosure).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."