XML Input Vulnerability in Oracle Web Applications Desktop Integrator
CVE-2024-21048
4.3MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 16 April 2024
Summary
An XML input vulnerability exists in the Oracle Web Applications Desktop Integrator component of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.13. This flaw allows low privileged attackers to exploit the system with network access via HTTP. Successful exploitation may lead to unauthorized read access, exposing sensitive data within the Oracle Web Applications Desktop Integrator. Organizations using the affected versions should implement the necessary mitigations as soon as possible to protect their systems.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published