Unauthenticated Access Vulnerability in Oracle Enterprise Manager UI Framework
CVE-2022-21469

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2022

Summary

An unauthenticated access vulnerability exists within the UI Framework of Oracle's Enterprise Manager Base Platform. This flaw allows an attacker with network access to exploit the system through HTTP. While the vulnerability is specifically in the Enterprise Manager Base Platform, its exploitation may have broader implications for other connected products. Successful exploitation requires user interaction from someone other than the attacker, leading to unauthorized ability to update, insert, or delete sensitive data in the platform. Organizations using versions 13.4.0.0 and 13.5.0.0 should be aware of these risks and take appropriate measures to mitigate potential impacts.

Affected Version(s)

Enterprise Manager Base Platform 13.4.0.0

Enterprise Manager Base Platform 13.5.0.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.