Unauthenticated Vulnerability in Oracle E-Business Suite's Maintenance Module
CVE-2024-21042

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 April 2024

Summary

An unauthenticated vulnerability exists in the Oracle Complex Maintenance, Repair, and Overhaul module of the Oracle E-Business Suite. This flaw allows an attacker with network access via HTTP to exploit the application, requiring human interaction from a user other than the attacker. While primarily affecting the Complex Maintenance and Repair module, successful exploitation could lead to unauthorized updates, inserts, or deletions of accessible data. Additionally, attackers may gain unauthorized read access to certain data sets, potentially compromising data integrity and confidentiality. Administrators should be aware of the potential risks and take appropriate remediation actions.

Affected Version(s)

Complex Maintenance, Repair, and Overhaul 12.2.3 <= 12.2.13

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.