Vulnerability in Oracle Common Applications Calendar for Oracle E-Business Suite
CVE-2021-2115
7.6HIGH
Summary
The Oracle Common Applications Calendar within the Oracle E-Business Suite is susceptible to exploitation that enables an attacker with limited privileges to gain unauthorized access through network channels such as HTTP. This vulnerability requires the active participation of a third party, which enhances the risk of data breaches. Impacted systems may suffer from unauthorized access not only to the calendar data but also could lead to manipulations such as data insertion, updates, or deletions, undermining the integrity and confidentiality of sensitive information.
Affected Version(s)
Common Applications Calendar 12.1.1-12.1.3
Common Applications Calendar 12.2.3-12.2.10
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved