Vulnerability in Oracle Partner Management Product of Oracle E-Business Suite
CVE-2022-21373

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 January 2022

Summary

An unauthenticated attacker with network access via HTTP can exploit a vulnerability in the Oracle Partner Management component of Oracle E-Business Suite. This easily exploitable flaw requires human interaction from a target user and can allow unauthorized updates, inserts, or deletions of data within Oracle Partner Management. Additionally, it can enable unauthorized read access to specific data sets, thereby significantly impacting the security of the system.

Affected Version(s)

Partner Management 12.2.3-12.2.11

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.