Unauthenticated Remote Code Execution in Oracle Enterprise Data Quality Dashboard
CVE-2022-21615

7.4HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 October 2022

Summary

An easily exploitable vulnerability exists in the Dashboard component of Oracle Enterprise Data Quality, allowing unauthenticated network access via HTTP. This vulnerability necessitates human interaction from a third party to facilitate the attack. While primarily affecting Oracle Enterprise Data Quality, successful exploitation may extend its impact to other connected Oracle products, leading to unauthorized access to critical data. Attackers may gain complete control over all data accessible within the Oracle Enterprise Data Quality environment.

Affected Version(s)

Enterprise Data Quality 12.2.1.3.0

Enterprise Data Quality 12.2.1.4.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.