Unauthenticated Vulnerability in Oracle E-Business Suite's Maintenance Module
CVE-2024-21042
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 16 April 2024
Summary
An unauthenticated vulnerability exists in the Oracle Complex Maintenance, Repair, and Overhaul module of the Oracle E-Business Suite. This flaw allows an attacker with network access via HTTP to exploit the application, requiring human interaction from a user other than the attacker. While primarily affecting the Complex Maintenance and Repair module, successful exploitation could lead to unauthorized updates, inserts, or deletions of accessible data. Additionally, attackers may gain unauthorized read access to certain data sets, potentially compromising data integrity and confidentiality. Administrators should be aware of the potential risks and take appropriate remediation actions.
Affected Version(s)
Complex Maintenance, Repair, and Overhaul 12.2.3 <= 12.2.13
References
CVSS V3.1
Timeline
Vulnerability published