Unauthenticated Data Exposure in Oracle E-Business Suite Trade Management
CVE-2024-21075
What is CVE-2024-21075?
A vulnerability exists in the Oracle Trade Management component of the Oracle E-Business Suite, specifically within the Claim Line List of Values (LOV). This flaw affects supported versions between 12.2.3 and 12.2.13. The vulnerability allows an unauthenticated attacker with network access via HTTP to exploit this flaw, potentially leading to unauthorized access to sensitive information. Exploitation of this vulnerability may result in a breach of confidentiality, enabling attackers to gain access to all data that Oracle Trade Management can access without any authentication.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Trade Management 12.2.3 <= 12.2.13
References
CVSS V3.1
Timeline
Vulnerability published