Unauthorized Access Vulnerability in Oracle E-Business Suite Mobile Field Service
CVE-2021-35570

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 October 2021

Summary

An easily exploitable vulnerability in the Oracle Mobile Field Service component of the Oracle E-Business Suite allows low privileged attackers with network access through HTTP to compromise the system. Successful exploitation of this vulnerability can lead to unauthorized creation, deletion, or modification of critical data, resulting in the potential exposure of all accessible data in Oracle Mobile Field Service.

Affected Version(s)

Mobile Field Service 12.1.1-12.1.3

Mobile Field Service 12.2.3-12.2.10

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.