Vulnerability in Oracle Database Server's Application Express Data Reporter
CVE-2021-2460
5.4MEDIUM
Summary
An exploitable vulnerability exists in the Oracle Application Express Data Reporter component of Oracle Database Server. This issue allows an attacker with valid user credentials and network access over HTTP to compromise the system. The vulnerability necessitates human interaction from an individual who is not the attacker. Successful exploitation can lead to unauthorized updates, insertion or deletion of data and unauthorized read access to certain data sets available within the Oracle Application Express Data Reporter. This could have broader implications for other dependent systems and data integrity.
Affected Version(s)
Application Express (APEX) < 21.1.0.00.04
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved