Vulnerability in Oracle Time and Labor of Oracle E-Business Suite
CVE-2021-2239

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 April 2021

Summary

An easily exploitable vulnerability exists in the Oracle Time and Labor component of Oracle E-Business Suite that allows an attacker with low privileges and network access through HTTP to compromise the system. This flaw enables unauthorized creation, deletion, or modification of critical data, resulting in potentially complete access to sensitive information within Oracle Time and Labor. The vulnerability primarily impacts multiple supported versions, highlighting the importance of timely updates and security measures.

Affected Version(s)

Time and Labor 12.1.1-12.1.3

Time and Labor 12.2.3-12.2.10

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.