4.3
CVE-2021-2017
- EPSS 0.3%
- Published 20.01.2021 15:15:46
- Last modified 21.11.2024 06:02:11
- Source secalert_us@oracle.com
- Teams watchlist Login
- Open Login
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle User Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Data is provided by the National Vulnerability Database (NVD)
Oracle ≫ Enterprise Data Quality Version11.1.1.9.0
Oracle ≫ Enterprise Data Quality Version12.2.1.3.0
Oracle ≫ Retail Invoice Matching Version13.2
Oracle ≫ Retail Invoice Matching Version14.0
Oracle ≫ Retail Invoice Matching Version14.1
Oracle ≫ User Management Version >= 12.2.3 <= 12.2.10
Oracle ≫ User Management Version12.1.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.3% | 0.531 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
secalert_us@oracle.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|