Vulnerability in Oracle E-Business Suite's View Reports Component
CVE-2021-35582

6.5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
20 October 2021

Summary

A security vulnerability in the Oracle Applications Manager, part of the Oracle E-Business Suite, could allow low-privileged attackers with network access via HTTP to compromise the system. Although the vulnerability resides in the View Reports component, successful exploitation may lead to unauthorized updates, inserts, or deletions of accessible data within Oracle Applications Manager. Furthermore, it could also enable unauthorized read access to certain datasets and potentially trigger a partial denial of service. Exploitation requires human interaction from a third party, making awareness vital for mitigating risks associated with this flaw. For more detailed information, refer to the Oracle security alerts.

Affected Version(s)

Applications Manager 12.1.3

Applications Manager 12.2.3-12.2.10

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.