Vulnerability in Oracle Engineering of Oracle E-Business Suite
CVE-2021-2405
8.1HIGH
Summary
A vulnerability exists in the Oracle Engineering component of Oracle E-Business Suite, where low-privileged attackers with network access via HTTP can exploit it. This vulnerability allows for unauthorized creation, deletion, or modification of critical data, potentially leading to extensive access to all Oracle Engineering accessible data. Organizations using affected versions 12.2.3 through 12.2.10 should prioritize remediation to safeguard against data breaches and unauthorized access.
Affected Version(s)
Engineering 12.2.3-12.2.10
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved