CVE-2024-21190: Critical severity oracle fusion middleware vulnerability
Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cloning). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SFTP to compromise Oracle Global Lifecycle Management FMW Installer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Global Lifecycle Management FMW Installer accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21190?
CVE-2024-21190 is classified as an easily exploitable vulnerability with significant potential impact.
Who is affected by CVE-2024-21190?
CVE-2024-21190 affects users of Oracle Fusion Middleware version 12.2.1.4.0.
How do I fix CVE-2024-21190?
To remediate CVE-2024-21190, you should apply the latest security patches provided by Oracle.
What type of attack is possible with CVE-2024-21190?
CVE-2024-21190 allows an unauthenticated attacker with network access via SFTP to compromise the Oracle Global Lifecycle Management FMW Installer.
Is there a workaround for CVE-2024-21190?
Currently, Oracle does not provide a specific workaround for CVE-2024-21190, so applying patches is recommended.