Vulnerability in Oracle Applications Manager of Oracle E-Business Suite
CVE-2021-35566

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 October 2021

Summary

The vulnerability in Oracle Applications Manager of Oracle E-Business Suite allows low-privileged attackers with network access to exploit the system via HTTP. This exploitation can lead to unauthorized creation, deletion, or modification of critical data. Successful exploitation grants attackers access to sensitive information, potentially impacting the confidentiality and integrity of all data accessible through Oracle Applications Manager. Support for vulnerable versions extends across several licensed editions, emphasizing the risk of unauthorized actions.

Affected Version(s)

Applications Manager 12.1.3

Applications Manager 12.2.3-12.2.10

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.