First published: Wed Jan 20 2021(Updated: )
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in takeover of Oracle Scripting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Scripting | >=12.1.1<=12.1.3 | |
Oracle Scripting | >=12.2.3<=12.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-2029 is considered an easily exploitable vulnerability due to its unauthenticated access via HTTP.
To remediate CVE-2021-2029, you should apply the latest security patches released by Oracle for the affected versions.
CVE-2021-2029 affects Oracle Scripting versions 12.1.1 to 12.1.3 and 12.2.3 to 12.2.8.
CVE-2021-2029 allows unauthenticated attackers with network access to compromise Oracle Scripting.
Yes, CVE-2021-2029 is a vulnerability within the Oracle Scripting product of the Oracle E-Business Suite.