Unauthenticated Remote Code Execution in Oracle Enterprise Data Quality Dashboard
CVE-2022-21615
7.4HIGH
Summary
An easily exploitable vulnerability exists in the Dashboard component of Oracle Enterprise Data Quality, allowing unauthenticated network access via HTTP. This vulnerability necessitates human interaction from a third party to facilitate the attack. While primarily affecting Oracle Enterprise Data Quality, successful exploitation may extend its impact to other connected Oracle products, leading to unauthorized access to critical data. Attackers may gain complete control over all data accessible within the Oracle Enterprise Data Quality environment.
Affected Version(s)
Enterprise Data Quality 12.2.1.3.0
Enterprise Data Quality 12.2.1.4.0
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved