Unauthenticated Input Vulnerability in Oracle E-Business Suite's Complex Maintenance, Repair, and Overhaul Product
CVE-2024-21034
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 16 April 2024
Summary
The vulnerability in Oracle's Complex Maintenance, Repair, and Overhaul component of the E-Business Suite allows an unauthenticated attacker with network access via HTTP to exploit the system. Successful exploitation requires user interaction from a third party, which increases the risk of unauthorized data manipulation, including the ability to update, insert, and delete certain data. Additionally, an attacker can gain unauthorized read access to sensitive data. This vulnerability not only affects the Complex Maintenance, Repair, and Overhaul product but also poses potential risks to interconnected systems, highlighting the need for urgent patching and comprehensive security measures.
Affected Version(s)
Complex Maintenance, Repair, and Overhaul 12.2.3 <= 12.2.13
References
CVSS V3.1
Timeline
Vulnerability published