Unauthorized Data Access Vulnerability in Oracle E-Business Suite iSupplier Portal
CVE-2023-21825
5.3MEDIUM
What is CVE-2023-21825?
An exploitable vulnerability exists in the Oracle iSupplier Portal, part of the Oracle E-Business Suite's Supplier Management component. This flaw allows unauthenticated attackers with network access via HTTP to potentially access restricted data. The affected versions (12.2.6 to 12.2.8) may expose sensitive information, leading to unauthorized read access to data within the portal. Organizations should assess their exposure to this vulnerability promptly and implement necessary security measures.
Affected Version(s)
iSupplier Portal 12.2.6-12.2.8