Unauthenticated HTTP Vulnerability in Oracle E-Business Suite Reports Configuration
CVE-2023-22004
4.3MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 18 July 2023
Summary
A significant vulnerability has been identified in the Oracle E-Business Suite, specifically within the Reports Configuration component. This issue allows unauthenticated attackers with network access via HTTP to exploit the system. Although the successful exploitation requires human interaction, it poses serious risks, as it can lead to unauthorized updates, insertions, or deletions of data within the Oracle Applications Technology framework. Organizations using supported versions between 12.2.3 and 12.2.12 are strongly advised to investigate and implement suitable security measures to mitigate potential risks.
Affected Version(s)
E-Business Suite Technology Stack 12.2.3 <= 12.2.12
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved