Unauthenticated Access Vulnerability in Oracle Configurator from Oracle
CVE-2021-2079
8.2HIGH
What is CVE-2021-2079?
Oracle Configurator, part of Oracle Supply Chain, contains a vulnerability that allows unauthenticated attackers to compromise the system through HTTP. This issue primarily affects versions 12.1 and 12.2, enabling unauthorized access to sensitive data. Although successful exploitation requires human interaction, the potential consequences can be severe, including complete access to all accessible data, unauthorized updates, inserts, or deletions within Oracle Configurator. This vulnerability poses significant risks not just to Oracle Configurator itself but may also impact other interrelated products.
Affected Version(s)
Configurator 12.1
Configurator 12.2