Unauthorized Data Access Vulnerability in Oracle E-Business Suite
CVE-2023-22076
6.1MEDIUM
Summary
A vulnerability exists in the Oracle Applications Framework of the Oracle E-Business Suite, primarily affecting versions 12.2.3 through 12.2.12. This vulnerability allows unauthenticated access to be exploited via HTTP, potentially leading to unauthorized updates, inserts, or deletions of available data. Although exploit attempts may require human interaction, the implications can extend beyond the framework, affecting other interconnected products. Security measures should be taken to prevent unauthorized reading of sensitive data accessible through the framework.
Affected Version(s)
Applications Framework 12.2.3 <= 12.2.12
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved