Unauthorized Access Vulnerability in Oracle E-Business Suite by Oracle
CVE-2021-2200

9.1CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 April 2021

Summary

A vulnerability exists in the Oracle Applications Framework component of Oracle E-Business Suite, specifically in version 12.2.10. This issue allows unauthenticated attackers with network access to compromise the framework via HTTP. Exploiting this vulnerability can result in unauthorized creation, deletion, or modification of critical data, granting attackers complete access to all data within the Oracle Applications Framework. This poses a significant risk to organizational data integrity and confidentiality.

Affected Version(s)

Applications Framework 12.2.10

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.