Unauthorized Access Vulnerability in Oracle Fusion Middleware Identity Manager
CVE-2021-2457

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 July 2021

Summary

An unauthorized access vulnerability exists within Oracle Fusion Middleware's Identity Manager component, specifically in Request Management & Workflow. This flaw allows an unauthenticated attacker to exploit the system over HTTP, potentially granting them unauthorized read access to certain sensitive data. The supported version known to be affected is 11.1.2.3.0. Organizations utilizing this software should implement necessary mitigations to prevent unauthorized access and protect their data integrity.

Affected Version(s)

Identity Manager 11.1.2.3.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.