Vulnerability in Oracle E-Business Suite APIs by Oracle
CVE-2024-21128

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 July 2024

Summary

This vulnerability affects the Oracle Application Object Library within the Oracle E-Business Suite APIs, allowing low-privileged attackers with HTTP network access to potentially compromise the library. The attack necessitates human interaction, which makes exploitation simpler. While primarily targeting the Application Object Library, the potential consequences of successful attacks can extend to other connected components, enabling unauthorized data manipulation such as updates, insertions, or deletions. Additionally, attackers may gain unauthorized read access to sensitive data contained within the library.

Affected Version(s)

Application Object Library 12.2.6 <= 12.2.13

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.