Unauthenticated Input Vulnerability in Oracle E-Business Suite's Complex Maintenance, Repair, and Overhaul Product
CVE-2024-21034

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 April 2024

Summary

The vulnerability in Oracle's Complex Maintenance, Repair, and Overhaul component of the E-Business Suite allows an unauthenticated attacker with network access via HTTP to exploit the system. Successful exploitation requires user interaction from a third party, which increases the risk of unauthorized data manipulation, including the ability to update, insert, and delete certain data. Additionally, an attacker can gain unauthorized read access to sensitive data. This vulnerability not only affects the Complex Maintenance, Repair, and Overhaul product but also poses potential risks to interconnected systems, highlighting the need for urgent patching and comprehensive security measures.

Affected Version(s)

Complex Maintenance, Repair, and Overhaul 12.2.3 <= 12.2.13

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.