CVE-2023-21997: Medium severity oracle user management vulnerability
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle User Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21997?
The severity of CVE-2023-21997 is medium with a severity value of 4.3.
What is the affected component of CVE-2023-21997?
The affected component of CVE-2023-21997 is Proxy User Delegation in Oracle User Management product of Oracle E-Business Suite.
Which versions of Oracle E-Business Suite are affected by CVE-2023-21997?
Versions 12.2.3 to 12.2.12 of Oracle E-Business Suite are affected by CVE-2023-21997.
How can a low privileged attacker exploit CVE-2023-21997?
A low privileged attacker with network access via HTTP can easily exploit CVE-2023-21997.
Where can I find more information about CVE-2023-21997?
You can find more information about CVE-2023-21997 at the following link: https://www.oracle.com/security-alerts/cpuapr2023.html