CVE-2023-21974: Critical severity oracle application express vulnerability
Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Team Calendar Plugin: 18.2-22.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Team Calendar Plugin. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Express Team Calendar Plugin, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Application Express Team Calendar Plugin. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Oracle Application Express Team Calendar Plugin vulnerability?
The vulnerability ID for this Oracle Application Express Team Calendar Plugin vulnerability is CVE-2023-21974.
What is the severity level of CVE-2023-21974?
The severity level of CVE-2023-21974 is critical.
Which versions of the Application Express Team Calendar Plugin are affected?
The affected versions of the Application Express Team Calendar Plugin are 18.2 to 22.1.
How can a low privileged attacker exploit this vulnerability?
A low privileged attacker with network access can easily exploit this vulnerability.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Oracle Security Alerts page: https://www.oracle.com/security-alerts/cpujul2023.html