Vulnerability in Oracle E-Business Suite APIs by Oracle
CVE-2024-21128
5.4MEDIUM
Summary
This vulnerability affects the Oracle Application Object Library within the Oracle E-Business Suite APIs, allowing low-privileged attackers with HTTP network access to potentially compromise the library. The attack necessitates human interaction, which makes exploitation simpler. While primarily targeting the Application Object Library, the potential consequences of successful attacks can extend to other connected components, enabling unauthorized data manipulation such as updates, insertions, or deletions. Additionally, attackers may gain unauthorized read access to sensitive data contained within the library.
Affected Version(s)
Application Object Library 12.2.6 <= 12.2.13
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published