Vulnerability in Oracle E-Business Suite Contract Lifecycle Management Affecting Data Security
CVE-2024-21278
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 15 October 2024
Summary
A significant vulnerability has been identified in the Oracle Contract Lifecycle Management for Public Sector, part of the Oracle E-Business Suite. This vulnerability impacts versions 12.2.3 through 12.2.13 and poses a risk to organizations using this software. The flaw allows low privileged attackers to exploit the system remotely via HTTP, potentially granting them unauthorized capabilities such as the creation, deletion, or alteration of critical data. Effective exploitation may lead to complete unauthorized access to all data managed by the Oracle Contract Lifecycle Management for Public Sector. Organizations are urged to assess their current versions and apply necessary updates to safeguard against potential breaches. Refer to Oracle's official advisory for further details and mitigation steps.
Affected Version(s)
Oracle Contract Lifecycle Management for Public Sector 12.2.3 <= 12.2.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved