Access Control Vulnerability in Oracle E-Business Suite Human Resources
CVE-2021-2365
8.1HIGH
Summary
A vulnerability exists in the Oracle Human Resources component of the Oracle E-Business Suite that could be exploited by low-privileged attackers with network access via HTTP. Successful exploitation of this vulnerability could enable unauthorized users to create, delete, or modify critical data. This compromise may lead to complete unauthorized access to all data managed by the Oracle Human Resources module, posing significant risks to data confidentiality and integrity.
Affected Version(s)
Human Resources 12.1.1-12.1.3
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved