Unauthenticated Vulnerability in Oracle E-Business Suite Common Applications Calendar
CVE-2021-2034
8.2HIGH
Summary
The Oracle Common Applications Calendar component of Oracle E-Business Suite is affected by an unauthenticated access vulnerability. An attacker with network access via HTTP could exploit this weakness, granting unauthorized access to sensitive data and potentially allowing unauthorized modifications. While the vulnerability primarily affects the Oracle Common Applications Calendar, it may also impact other associated components. Successful exploitation requires human interaction from a user other than the attacker, underscoring the need for vigilance and improved security measures to protect sensitive information.
Affected Version(s)
Common Applications Calendar 12.1.1-12.1.3
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved