Unauthorized Access Vulnerability in Oracle E-Business Suite by Oracle
CVE-2021-2200
9.1CRITICAL
Summary
A vulnerability exists in the Oracle Applications Framework component of Oracle E-Business Suite, specifically in version 12.2.10. This issue allows unauthenticated attackers with network access to compromise the framework via HTTP. Exploiting this vulnerability can result in unauthorized creation, deletion, or modification of critical data, granting attackers complete access to all data within the Oracle Applications Framework. This poses a significant risk to organizational data integrity and confidentiality.
Affected Version(s)
Applications Framework 12.2.10
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved