Unauthenticated Access Vulnerability in Oracle One-to-One Fulfillment
CVE-2021-2100
9.1CRITICAL
Summary
The vulnerability in the Oracle One-to-One Fulfillment product of the Oracle E-Business Suite allows an unauthenticated attacker with network access via HTTP to effectively compromise the application. This weakness leads to the potential for unauthorized actions, including the creation, deletion, or modification of sensitive data. Successful exploitation allows attackers to attain complete operational access to all data within Oracle One-to-One Fulfillment, raising significant security concerns regarding data confidentiality and integrity.
Affected Version(s)
One-to-One Fulfillment 12.1.1-12.1.3
One-to-One Fulfillment 12.2.3-12.2.10
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved