First published: Tue Oct 15 2024(Updated: )
Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cloning). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SFTP to compromise Oracle Global Lifecycle Management FMW Installer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Global Lifecycle Management FMW Installer accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Fusion Middleware | =12.2.1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21190 is classified as an easily exploitable vulnerability with significant potential impact.
CVE-2024-21190 affects users of Oracle Fusion Middleware version 12.2.1.4.0.
To remediate CVE-2024-21190, you should apply the latest security patches provided by Oracle.
CVE-2024-21190 allows an unauthenticated attacker with network access via SFTP to compromise the Oracle Global Lifecycle Management FMW Installer.
Currently, Oracle does not provide a specific workaround for CVE-2024-21190, so applying patches is recommended.