First published: Tue Apr 16 2024(Updated: )
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. While the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 4.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Commerce Platform | =11.3.0 | |
Oracle Commerce Platform | =11.3.1 | |
Oracle Commerce Platform | =11.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21100 is considered a difficult to exploit vulnerability affecting Oracle Commerce Platform.
To fix CVE-2024-21100, it is recommended to upgrade to the latest supported version of Oracle Commerce Platform.
CVE-2024-21100 affects Oracle Commerce Platform versions 11.3.0, 11.3.1, and 11.3.2.
CVE-2024-21100 can be exploited by an unauthenticated attacker with network access via HTTP.
CVE-2024-21100 impacts the Platform component of the Oracle Commerce product.