Unauthenticated Access Vulnerability in Oracle E-Business Suite's Oracle Applications Framework
CVE-2022-21566

7.5HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 July 2022

Summary

An unauthenticated access vulnerability exists within the Oracle Applications Framework component of Oracle E-Business Suite, affecting versions 12.2.9 to 12.2.11. This flaw permits an attacker with network access to HTTP to compromise the system, potentially leading to unauthorized access to sensitive data. A successful exploitation could provide complete access to all data that is accessible through the Oracle Applications Framework, making it critical for organizations to apply security patches provided by Oracle to mitigate risks.

Affected Version(s)

Applications Framework 12.2.9-12.2.11

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.