Unauthorized Data Access in Oracle E-Business Suite's User Management Component
CVE-2021-2017
4.3MEDIUM
Summary
The vulnerability in Oracle User Management, part of Oracle E-Business Suite, allows low privileged attackers with network access through HTTP to potentially compromise user management functionalities. Attackers exploiting this flaw may gain unauthorized read access to various subsets of data within the product. The affected versions include 12.1.3 and ranges from 12.2.3 to 12.2.10, making it essential for users to apply security patches and protective measures to safeguard sensitive information.
Affected Version(s)
User Management 12.1.3
User Management 12.2.3-12.2.10
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved