First published: Wed Oct 20 2021(Updated: )
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: View Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Manager accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Applications Manager | >=12.2.3<=12.2.10 | |
Oracle Applications Manager | =12.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35581 is classified as a high severity vulnerability due to its potential for easy exploitation by unauthenticated attackers.
To fix CVE-2021-35581, upgrade Oracle Applications Manager to the latest patched version, ensuring to follow Oracle's recommended security guidelines.
CVE-2021-35581 affects Oracle Applications Manager versions 12.1.3 and 12.2.3 through 12.2.10.
Yes, CVE-2021-35581 can be exploited remotely by an unauthenticated attacker with network access via HTTP.
The vulnerable component in CVE-2021-35581 is the View Reports feature of Oracle Applications Manager.