Vulnerability in Oracle E-Business Suite APIs Affects Oracle Installed Base
CVE-2021-2023
4.7MEDIUM
Summary
A vulnerability exists in the Oracle Installed Base component of the Oracle E-Business Suite, where an unauthenticated attacker with network access via HTTP may exploit it. The attack requires human interaction from an individual other than the attacker, leading to potential unauthorized changes to data, including updates, inserts, and deletions. Although this vulnerability primarily affects the Installed Base, the ramifications can extend to other related Oracle products, emphasizing the need for awareness and remediation.
Affected Version(s)
Installed Base 12.1.1-12.1.3
Installed Base 12.2.3-12.2.9
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved