Unauthenticated Remote Code Execution Vulnerability in Oracle E-Business Suite Scripting
CVE-2021-2029
9.8CRITICAL
Summary
A vulnerability exists in the Oracle Scripting component of Oracle E-Business Suite, which can be exploited by an unauthenticated attacker with network access via HTTP. The vulnerability allows for the potential takeover of Oracle Scripting, potentially jeopardizing confidentiality, integrity, and availability of the system. Supported versions affected include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.8. Organizations using these versions should promptly apply patches and assess their security posture.
Affected Version(s)
Scripting 12.1.1-12.1.3
Scripting 12.2.3-12.2.8
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved