Vulnerability in Oracle Financial Services Analytical Applications Infrastructure
CVE-2021-35686
4.3MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 January 2022
Summary
The vulnerability in Oracle Financial Services Analytical Applications Infrastructure, specifically within the Unified Metadata Manager component, allows low privileged attackers with network access via HTTP to gain unauthorized read access to a subset of sensitive data. Affected versions include 8.0.7 through 8.1.1. This security flaw can significantly impact the confidentiality of the data managed by the application, permitting potential exposure to unauthorized entities.
Affected Version(s)
Financial Services Analytical Applications Infrastructure 8.0.7-8.1.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved