Vulnerability in Oracle E-Business Suite affecting CRM Technical Foundation
CVE-2021-2085
8.2HIGH
Summary
An exploitable vulnerability in Oracle CRM Technical Foundation allows an unauthenticated attacker with network access via HTTP to compromise the system. While the primary target is the CRM Technical Foundation, successful exploitation can lead to unauthorized access and manipulation of critical data across connected products. Exploits require human interaction, making awareness and vigilance crucial for protection. Attackers may gain the ability to update, insert, or delete sensitive data, posing significant risks to organizational data integrity.
Affected Version(s)
CRM Technical Foundation 12.1.3
CRM Technical Foundation 12.2.3-12.2.10
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved