CVE-2024-21024
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-21024 is a newly identified vulnerability affecting the Oracle Complex Maintenance, Repair, and Overhaul component of Oracle E-Business Suite, specifically versions 12.2.3 to 12.2.13. This vulnerability, which has a base score of 6.1 (Confidentiality and Integrity impacts), is easily exploitable and allows unauthenticated attackers with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction, and while limited to Oracle Complex Maintenance, Repair, and Overhaul, they could significantly impact other affected products. This vulnerability enables unauthorized access, enabling attackers to update, insert, or delete data, as well as unauthorized read access to a subset of data within Oracle Complex Maintenance, Repair, and Overhaul.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.