Unauthenticated Network Access Vulnerability in Oracle E-Business Suite
CVE-2024-21027

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 April 2024

Summary

This vulnerability in Oracle's Complex Maintenance, Repair, and Overhaul component of Oracle E-Business Suite allows an unauthenticated attacker with network access through HTTP to potentially exploit the system. While the vulnerability specifically targets the Oracle Complex Maintenance, Repair, and Overhaul product, successful exploitation can have broader implications across related products. The attack requires some form of human interaction, making it particularly deceptive. Attackers may gain unauthorized capabilities such as updating, inserting, or deleting accessible data, as well as acquiring read access to some sensitive data within the system, thus threatening the confidentiality and integrity of information.

Affected Version(s)

Complex Maintenance, Repair, and Overhaul 12.2.3 <= 12.2.13

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.