Unauthenticated Access Flaw in Oracle iStore User Management
CVE-2024-21143

5.3MEDIUM

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
16 July 2024

Summary

A vulnerability exists in the User Management component of Oracle iStore within the Oracle E-Business Suite. This flaw allows an unauthenticated attacker with network access via HTTP to potentially exploit Oracle iStore. Successful exploitation could lead to unauthorized access to sensitive data, making personal and corporate information at risk. The affected versions include Oracle iStore from 12.2.3 to 12.2.13. Organizations using these versions should review their security measures immediately.

Affected Version(s)

iStore 12.2.3 <= 12.2.13

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.