Vulnerability in Oracle Web Applications Desktop Integrator Affects Oracle E-Business Suite
CVE-2023-21847

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2023

Summary

A vulnerability exists in Oracle Web Applications Desktop Integrator affecting the Oracle E-Business Suite, specifically allowing low privileged attackers with network access via HTTP to compromise the application. Exploitation requires human interaction from a user other than the attacker, and though the vulnerability is contained within the Web Applications Desktop Integrator, its ramifications can extend to other products. Successful attacks can lead to unauthorized updates, inserts, or deletions, as well as unauthorized read access to certain accessible data within the application.

Affected Version(s)

Web Applications Desktop Integrator 12.2.3-12.2.12

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.