Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents)
Published Apr 22, 2021
4.3
MEDIUMCVSS 3.1
EPSS 0.78%
Description
Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
Affected products
-
- Version 12.1.1-12.1.3StatusaffectedConstraints-
- Version 12.2.3-12.2.10StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Oracle Corporation | One-to-One Fulfillment | n/a |
|
- ≥ 12.1.1 · ≤ 12.1.3
- ≥ 12.2.3 · ≤ 12.2.10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-16614 Advisory
- https://www.oracle.com/security-alerts/cpuapr2021.html x_refsource_MISCPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-16614 | Advisory | |
| https://www.oracle.com/security-alerts/cpuapr2021.html | x_refsource_MISCPatchVendor Advisory |
Change history (0)
No recorded changes yet.