Unauthenticated Access Vulnerability in Oracle Applications Manager of Oracle E-Business Suite
CVE-2021-35580

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 October 2021

Summary

Oracle Applications Manager, part of the Oracle E-Business Suite, is vulnerable to an unauthenticated access flaw that could be exploited by attackers. The vulnerability allows a network-accessible attacker to compromise the application, potentially leading to unauthorized modifications and data access. This requires human interaction from another individual to succeed. Affected versions include 12.1.3 and 12.2.3 through 12.2.10, highlighting the need for all users to review their security configurations and apply appropriate mitigations to safeguard sensitive information.

Affected Version(s)

Applications Manager 12.1.3

Applications Manager 12.2.3-12.2.10

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.