Unauthorized Access Vulnerability in Oracle Marketing of Oracle E-Business Suite
CVE-2024-21079
7.5HIGH
Summary
A vulnerability in the Oracle Marketing component of Oracle E-Business Suite allows unauthenticated attackers with network access via HTTP to exploit weaknesses in the system. Specifically, this flaw affects supported versions from 12.2.3 to 12.2.13, granting potential attackers unauthorized access to sensitive data. Successful exploitation can lead to unauthorized disclosure of critical information and full access to all data accessible within Oracle Marketing, representing a significant security risk for organizations relying on this application.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published