Vulnerability in Oracle Application Express Administration Allows Unauthorized Access
CVE-2023-21983

5.6MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2023

Summary

A vulnerability in Oracle's Application Express Administration allows an unauthenticated attacker with network access via HTTP to potentially compromise system security. This vulnerability could enable unauthorized operations such as updates, inserts, or deletions of accessible data. Additionally, it could allow unauthorized read access to certain data subsets and even lead to a partial denial of service. Organizations utilizing affected versions of Application Express Administration should assess their exposure and apply appropriate security measures to mitigate risks.

Affected Version(s)

Application Express (APEX) Application Express Administration: 18.2 <= 22.2

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.