Unprotected Access in Oracle Financial Services Analytical Applications Infrastructure
CVE-2021-2140

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 April 2021

Summary

This vulnerability allows an unauthenticated attacker with network access to the Oracle Financial Services Analytical Applications Infrastructure to potentially compromise the system. The exploitation of this flaw requires human interaction from a third party, which makes it a unique security concern. A successful attack could lead to unauthorized data modifications, including updates, inserts, or deletions, along with the ability to read sensitive data. The impact of this vulnerability extends beyond the affected component, as it may influence other products within the Oracle ecosystem.

Affected Version(s)

Financial Services Analytical Applications Infrastructure 8.0.6-8.1.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.