Vulnerability in Oracle E-Business Suite's Enterprise Command Center Framework
CVE-2023-22107

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2023

Summary

An unauthenticated access vulnerability exists in the Oracle Enterprise Command Center Framework found in Oracle E-Business Suite. This weakness allows attackers with network access via HTTP to exploit the framework, necessitating a specific human interaction from an individual other than the attacker for successful exploitation. While the vulnerability lies within the Oracle Enterprise Command Center Framework itself, it has the potential to affect other connected products significantly. Successful exploitation could lead to unauthorized data manipulation actions, including updates, inserts, and deletions, as well as unauthorized access to confidential information within the framework.

Affected Version(s)

Enterprise Command Center Framework ECC: 8

Enterprise Command Center Framework 9

Enterprise Command Center Framework 10

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.