PT-2021-1793 · Oracle · Oracle Argus Safety
Published
2021-01-20
·
Updated
2021-01-26
·
CVE-2021-2040
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Oracle Argus Safety version 8.2.2
Description:
The issue exists due to insufficient input validation in the Case Form and Local Affiliate Form components of Oracle Argus Safety. This allows a remote attacker to gain read access to data or modify data using specially crafted HTTP requests. Successful attacks require human interaction and may significantly impact additional products, resulting in unauthorized update, insert, or delete access to some data, as well as unauthorized read access to a subset of data.
Recommendations:
For Oracle Argus Safety version 8.2.2, consider restricting access to the Case Form and Local Affiliate Form components until a patch is available. As a temporary workaround, limit the use of HTTP requests to these components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Argus Safety