Unauthorized Data Access Vulnerability in Oracle E-Business Suite
CVE-2023-22076
6.1MEDIUM
What is CVE-2023-22076?
A vulnerability exists in the Oracle Applications Framework of the Oracle E-Business Suite, primarily affecting versions 12.2.3 through 12.2.12. This vulnerability allows unauthenticated access to be exploited via HTTP, potentially leading to unauthorized updates, inserts, or deletions of available data. Although exploit attempts may require human interaction, the implications can extend beyond the framework, affecting other interconnected products. Security measures should be taken to prevent unauthorized reading of sensitive data accessible through the framework.
Affected Version(s)
Applications Framework 12.2.3 <= 12.2.12