Vulnerability in Oracle E-Business Suite Cost Management Could Compromise Sensitive Data
CVE-2024-21267
Summary
A serious vulnerability exists in the Oracle Cost Management component of the Oracle E-Business Suite, specifically affecting versions 12.2.12 and 12.2.13. This vulnerability can be easily exploited by a low-privileged attacker with network access via HTTP, posing a significant risk to organizations relying on this software. Successful exploitation may lead to unauthorized creation, deletion, and modification of critical data, as well as complete access to sensitive information within Oracle Cost Management. The potential impacts on confidentiality and integrity are severe, making it imperative for users to apply the necessary security updates and mitigations as outlined in Oracle's advisory.
Affected Version(s)
Oracle Cost Management 12.2.12 <= 12.2.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved