Unauthorized Access Vulnerability in Oracle E-Business Suite
CVE-2021-2314

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 April 2021

Summary

An authorization bypass vulnerability exists in the Oracle Application Object Library component of Oracle E-Business Suite. This vulnerability affects versions 12.1.3 and 12.2.3 through 12.2.10. It allows a low-privileged attacker with network access via HTTP to exploit the flaw and gain unauthorized access, potentially compromising or modifying critical data. Successful exploitation can lead to significant data integrity issues, allowing attackers to create, delete, or modify data without appropriate permissions.

Affected Version(s)

Application Object Library 12.1.3

Application Object Library 12.2.3-12.2.10

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.