Unauthorized Access Vulnerability in Oracle Trade Management by Oracle
CVE-2021-2206

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 April 2021

Summary

The vulnerability in Oracle Trade Management within the Oracle E-Business Suite can be exploited via HTTP, allowing an unauthenticated attacker to potentially gain unauthorized access to sensitive data. While the initial vulnerability lies within the Oracle Trade Management component, successful exploitation can have significant repercussions on other integrated products. The exploitation path involves social engineering—requiring human interaction from a third party—therefore increasing the complexity of successful attacks. As a result, the impact of this vulnerability could include unauthorized read, update, insert, or delete actions on critical data, raising significant security concerns for organizations utilizing Oracle's solutions.

Affected Version(s)

Trade Management 12.1.1-12.1.3

Trade Management 12.2.3-12.2.10

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.