Vulnerability in Oracle E-Business Suite Service Contracts Component
CVE-2021-2255

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 April 2021

Summary

A vulnerability exists in the Oracle Service Contracts component of the Oracle E-Business Suite that allows a low-privileged attacker with network access to exploit the system via HTTP. This exploitation can lead to unauthorized creation, deletion, or modification of data within Oracle Service Contracts. Attackers may gain access to sensitive information and potentially compromise the integrity and confidentiality of critical data. Supported versions 12.1.1 to 12.1.3 are affected, highlighting the importance of prompt patching and security measures.

Affected Version(s)

Service Contracts 12.1.1-12.1.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.