Workflow Events Vulnerability in Oracle E-Business Suite Shipping Execution
CVE-2021-35563
8.1HIGH
Summary
A vulnerability exists within the Workflow Events component of Oracle Shipping Execution in the Oracle E-Business Suite, affecting versions 12.2.6 through 12.2.10. This vulnerability is particularly concerning as it can be exploited by low privileged attackers with HTTP network access to gain unauthorized control over sensitive data. Successful exploitation allows attackers to create, delete, or modify critical data, posing severe risks to data integrity and confidentiality within the Oracle Shipping Execution environment.
Affected Version(s)
Shipping Execution 12.2.6-12.2.10
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved