Unauthenticated Access Vulnerability in Oracle One-to-One Fulfillment
CVE-2021-2100

9.1CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 January 2021

Summary

The vulnerability in the Oracle One-to-One Fulfillment product of the Oracle E-Business Suite allows an unauthenticated attacker with network access via HTTP to effectively compromise the application. This weakness leads to the potential for unauthorized actions, including the creation, deletion, or modification of sensitive data. Successful exploitation allows attackers to attain complete operational access to all data within Oracle One-to-One Fulfillment, raising significant security concerns regarding data confidentiality and integrity.

Affected Version(s)

One-to-One Fulfillment 12.1.1-12.1.3

One-to-One Fulfillment 12.2.3-12.2.10

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.