First published: Tue Jul 19 2022(Updated: )
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Workflow accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Workflow | >=12.2.3<=12.2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-21567.
The vulnerability affects the Oracle Workflow product of Oracle E-Business Suite.
The vulnerability affects versions 12.2.3 to 12.2.11 of Oracle E-Business Suite.
An unauthenticated attacker with network access via HTTP can exploit the vulnerability.
The severity of the vulnerability is high, with a CVSS score of 7.5.
You can find more information about the vulnerability on the Oracle Security Alerts website.