CVE-2024-21021: XSS
Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Complex Maintenance, Repair, and Overhaul accessible data as well as unauthorized read access to a subset of Oracle Complex Maintenance, Repair, and Overhaul accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21021?
The severity of CVE-2024-21021 is high due to its potential for exploitation by unauthenticated attackers via HTTP.
How do I fix CVE-2024-21021?
To fix CVE-2024-21021, upgrade to a supported version of Oracle Complex Maintenance, Repair, and Overhaul that is not affected.
What versions of Oracle Complex Maintenance, Repair, and Overhaul are affected by CVE-2024-21021?
The affected versions of Oracle Complex Maintenance, Repair, and Overhaul are from 12.2.3 to 12.2.13.
Who is impacted by CVE-2024-21021?
Organizations using Oracle E-Business Suite versions 12.2.3 to 12.2.13 are impacted by CVE-2024-21021.
Can CVE-2024-21021 be exploited remotely?
Yes, CVE-2024-21021 can be exploited remotely by an unauthenticated attacker with network access via HTTP.