Oracle Service Contracts Vulnerability: Confidentiality and Integrity at Risk
CVE-2024-21280
8.1HIGH
What is CVE-2024-21280?
This vulnerability resides within the Oracle Service Contracts component of the Oracle E-Business Suite, impacting versions 12.2.5 through 12.2.13. It enables low-privileged attackers with network access via HTTP to exploit weaknesses in the system. This could lead to unauthorized creation, deletion, or modification of critical data associated with all Oracle Service Contracts. Successful exploitation permits attackers to gain complete access to sensitive data stored in the affected product, posing significant risks to data confidentiality and integrity.
Affected Version(s)
Oracle Service Contracts 12.2.5 <= 12.2.13