Unauthenticated Remote Code Execution in Oracle Enterprise Data Quality by Oracle
CVE-2022-21613

8.8HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 October 2022

Summary

This vulnerability in Oracle Enterprise Data Quality allows an unauthenticated attacker to exploit the system through HTTP, necessitating human interaction from a third party. While primarily affecting Oracle Enterprise Data Quality, the consequences could extend to other connected applications. Attackers can gain unauthorized access to sensitive data, execute unintended updates, or delete information within the system. Furthermore, this vulnerability may lead to reduced service availability, jeopardizing the integrity and confidentiality of critical data assets.

Affected Version(s)

Enterprise Data Quality 12.2.1.3.0

Enterprise Data Quality 12.2.1.4.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.