Vulnerability in Oracle CRM Technical Foundation Product by Oracle
CVE-2021-2092
8.2HIGH
Summary
An exploitable vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite allows unauthenticated attackers with network access via HTTP to potentially compromise sensitive data. Successful exploitation requires human interaction from a user other than the attacker and may lead to unauthorized access to critical data, allowing for data modification, deletion, or insertion. This vulnerability affects multiple supported versions of the product and poses significant risks since an attacker can gain extensive privileges over accessible information.
Affected Version(s)
CRM Technical Foundation 12.1.3
CRM Technical Foundation 12.2.3-12.2.10
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved