Unauthorized Data Access in Oracle E-Business Suite's User Management Component
CVE-2021-2017

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 January 2021

Summary

The vulnerability in Oracle User Management, part of Oracle E-Business Suite, allows low privileged attackers with network access through HTTP to potentially compromise user management functionalities. Attackers exploiting this flaw may gain unauthorized read access to various subsets of data within the product. The affected versions include 12.1.3 and ranges from 12.2.3 to 12.2.10, making it essential for users to apply security patches and protective measures to safeguard sensitive information.

Affected Version(s)

User Management 12.1.3

User Management 12.2.3-12.2.10

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.