User Management Vulnerability in Oracle E-Business Suite
CVE-2023-21997

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 April 2023

Summary

A vulnerability within the Oracle User Management component of the Oracle E-Business Suite allows low-privileged attackers to exploit network access via HTTP. This can lead to unauthorized read access to a limited set of sensitive data in the User Management system, potentially compromising the integrity and confidentiality of the affected applications. With versions from 12.2.3 to 12.2.12 susceptible, organizations using these are advised to apply security patches promptly to mitigate risks associated with this flaw.

Affected Version(s)

User Management 12.2.3-12.2.12

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.