Unauthenticated Access Vulnerability in Oracle E-Business Suite's Installed Base Component
CVE-2024-20934
6.1MEDIUM
Summary
A vulnerability exists in the Oracle Installed Base component of the Oracle E-Business Suite that allows unauthenticated attackers with network access via HTTP to compromise sensitive data. Successful exploitation hinges on human interaction from an uninvolved party and can lead to unauthorized data manipulation, including the ability to update, insert, or delete data. Although the vulnerability resides within the Oracle Installed Base, the consequences may extend to other products, thereby broadening the scope of potential impacts.
Affected Version(s)
Installed Base 12.2.3 <= 12.2.13
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved