Unauthenticated Remote Code Execution in Oracle E-Business Suite - CRM User Management Framework
CVE-2021-2436
8.2HIGH
What is CVE-2021-2436?
A vulnerability in the Oracle Common Applications component of Oracle E-Business Suite's CRM User Management Framework allows an unauthenticated attacker with network access via HTTP to compromise the application. This vulnerability can potentially lead to unauthorized access to sensitive data across various Oracle applications. Successful exploitation requires human interaction from a victim, enhancing its risk profile. Attackers could achieve unauthorized updates, inserts, or deletions of accessible data within the Oracle Common Applications, impacting the confidentiality and integrity of the entire system.
Affected Version(s)
Common Applications 12.1.1-12.1.3
Common Applications 12.2.3-12.2.10