Unauthorized Data Access Vulnerability in Oracle E-Business Suite
CVE-2023-22076

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2023

Summary

A vulnerability exists in the Oracle Applications Framework of the Oracle E-Business Suite, primarily affecting versions 12.2.3 through 12.2.12. This vulnerability allows unauthenticated access to be exploited via HTTP, potentially leading to unauthorized updates, inserts, or deletions of available data. Although exploit attempts may require human interaction, the implications can extend beyond the framework, affecting other interconnected products. Security measures should be taken to prevent unauthorized reading of sensitive data accessible through the framework.

Affected Version(s)

Applications Framework 12.2.3 <= 12.2.12

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.