Oracle Service Contracts Vulnerability: Confidentiality and Integrity at Risk
CVE-2024-21280
8.1HIGH
Summary
This vulnerability resides within the Oracle Service Contracts component of the Oracle E-Business Suite, impacting versions 12.2.5 through 12.2.13. It enables low-privileged attackers with network access via HTTP to exploit weaknesses in the system. This could lead to unauthorized creation, deletion, or modification of critical data associated with all Oracle Service Contracts. Successful exploitation permits attackers to gain complete access to sensitive data stored in the affected product, posing significant risks to data confidentiality and integrity.
Affected Version(s)
Oracle Service Contracts 12.2.5 <= 12.2.13
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database