CVE-2024-21073: Infoleak
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21073?
CVE-2024-21073 is classified as an easily exploitable vulnerability that can significantly compromise Oracle Trade Management.
How does CVE-2024-21073 affect Oracle Trade Management?
CVE-2024-21073 allows an unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management.
What versions of Oracle E-Business Suite are affected by CVE-2024-21073?
CVE-2024-21073 affects Oracle E-Business Suite versions 12.2.3 through 12.2.13.
How do I fix CVE-2024-21073?
To address CVE-2024-21073, users should apply the latest security patches provided by Oracle for the affected versions.
Is network access required to exploit CVE-2024-21073?
Yes, CVE-2024-21073 can be exploited by an attacker with network access to the affected system via HTTP.