User Interface Vulnerability in Oracle Transportation Management by Oracle
CVE-2022-21480

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2022

Summary

A vulnerability within the Oracle Transportation Management product allows unauthenticated attackers with network access via HTTP to exploit weaknesses in the user interface. This issue can lead to unauthorized modifications, including updates, insertions, or deletions of data, alongside unauthorized read access to sensitive information within Oracle Transportation Management. Successful exploitation does require human interaction, which increases the complexity of the attack. It has broader implications as it may affect related systems connected to Oracle Transportation Management.

Affected Version(s)

Transportation Management 6.4.3

Transportation Management 6.5.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.