Vulnerability in Oracle Email Center within Oracle E-Business Suite
CVE-2021-2209
8.5HIGH
Summary
A vulnerability exists in the Oracle Email Center component of Oracle E-Business Suite, affecting several supported versions. This flaw allows low-privileged attackers with network access through HTTP to compromise the system, potentially leading to unauthorized access to sensitive information and the ability to perform unauthorized operations such as updates, insertions, or deletions of data. Consequently, not only does this affect Oracle Email Center data, but it may also pose risks to interconnected products within the E-Business Suite ecosystem.
Affected Version(s)
Email Center 12.1.1-12.1.3
Email Center 12.2.3-12.2.10
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved