CVE-2024-21267: High severity oracle e-business suite vulnerability
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Cost Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Cost Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21267?
CVE-2024-21267 is categorized as an easily exploitable vulnerability allowing low privileged access.
How do I fix CVE-2024-21267?
To mitigate CVE-2024-21267, upgrade Oracle E-Business Suite from versions 12.2.12-12.2.13 to a supported version.
What versions of Oracle E-Business Suite are affected by CVE-2024-21267?
CVE-2024-21267 affects Oracle E-Business Suite versions 12.2.12 and 12.2.13.
Who can exploit CVE-2024-21267?
CVE-2024-21267 can be exploited by an attacker with low privileges and network access via HTTP.
What component of Oracle E-Business Suite is impacted by CVE-2024-21267?
CVE-2024-21267 specifically impacts the Cost Planning component of the Oracle Cost Management product.