Vulnerability in Oracle Financial Services Analytical Applications Infrastructure
CVE-2021-35686

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 January 2022

Summary

The vulnerability in Oracle Financial Services Analytical Applications Infrastructure, specifically within the Unified Metadata Manager component, allows low privileged attackers with network access via HTTP to gain unauthorized read access to a subset of sensitive data. Affected versions include 8.0.7 through 8.1.1. This security flaw can significantly impact the confidentiality of the data managed by the application, permitting potential exposure to unauthorized entities.

Affected Version(s)

Financial Services Analytical Applications Infrastructure 8.0.7-8.1.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.