Vulnerability in Oracle E-Business Suite Contract Lifecycle Management Affecting Data Security
CVE-2024-21278

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 October 2024

Summary

A significant vulnerability has been identified in the Oracle Contract Lifecycle Management for Public Sector, part of the Oracle E-Business Suite. This vulnerability impacts versions 12.2.3 through 12.2.13 and poses a risk to organizations using this software. The flaw allows low privileged attackers to exploit the system remotely via HTTP, potentially granting them unauthorized capabilities such as the creation, deletion, or alteration of critical data. Effective exploitation may lead to complete unauthorized access to all data managed by the Oracle Contract Lifecycle Management for Public Sector. Organizations are urged to assess their current versions and apply necessary updates to safeguard against potential breaches. Refer to Oracle's official advisory for further details and mitigation steps.

Affected Version(s)

Oracle Contract Lifecycle Management for Public Sector 12.2.3 <= 12.2.13

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.