First published: Wed Oct 20 2021(Updated: )
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Oracle E-Business Suite. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of the Content-Length HTTP header. The issue results from the lack of proper validation of user-supplied data, which can result in a memory exhaustion condition. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Sales Offline | >=12.1.1<=12.1.3 | |
Oracle Sales Offline | >=12.2.3<=12.2.10 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35611 is a vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite that allows a low privileged attacker with network access via HTTP to compromise Oracle Sales Offline, resulting in denial-of-service.
The affected versions of Oracle E-Business Suite are 12.1.1-12.1.3 and 12.2.3-12.2.10.
The severity of CVE-2021-35611 is medium, with a severity value of 4.3.
A low privileged attacker with network access via HTTP can exploit CVE-2021-35611 to compromise Oracle Sales Offline and cause denial-of-service.
You can find more information about CVE-2021-35611 on the Oracle Security Alerts page at https://www.oracle.com/security-alerts/cpuoct2021.html and the Zero Day Initiative advisories page at https://www.zerodayinitiative.com/advisories/ZDI-21-1231/.