Weakness in Oracle E-Business Suite's Enterprise Asset Management Component
CVE-2024-21149

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 July 2024

Summary

A significant vulnerability exists within the Oracle E-Business Suite, specifically affecting the Enterprise Asset Management component. Supported versions from 12.2.11 to 12.2.13 are vulnerable due to a flaw that allows a low privileged attacker with network access via HTTP the ability to compromise the application. This vulnerability can lead to unauthorized creation, deletion, or modification of critical data, as well as the potential for full access to all data that is accessible within the Oracle Enterprise Asset Management system. Organizations should prioritize patching to mitigate risks to data confidentiality and integrity.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.