Oracle E-Business Suite Vulnerability in Complex Maintenance, Repair, and Overhaul
CVE-2024-21016

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 April 2024

Summary

An exploitable vulnerability exists in the Oracle Complex Maintenance, Repair, and Overhaul component of Oracle E-Business Suite. This issue affects versions 12.2.3 through 12.2.13, allowing an unauthenticated attacker with network access to compromise the affected product via HTTP. Successful exploitation requires human interaction from a third party, but the vulnerability can lead to unauthorized alterations to data and unauthorized read access to sensitive information. Attackers may be able to impact additional products due to the scope of the vulnerability.

Affected Version(s)

Complex Maintenance, Repair, and Overhaul 12.2.3 <= 12.2.13

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.