PT-2021-2808 · Oracle · Oracle E-Business Suite+1
Published
2021-04-20
·
Updated
2021-04-29
·
CVE-2021-2260
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle E-Business Suite versions 12.1.3
Description
The issue is related to inadequate access control in the iRecruitment component of Oracle Human Resources, allowing a low-privileged attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Human Resources accessible data, as well as unauthorized access to critical data or complete access to all Oracle Human Resources accessible data.
Recommendations
For version 12.1.3, consider restricting access to the iRecruitment component until a patch is available to minimize the risk of exploitation. Additionally, review and strengthen access controls for Oracle Human Resources to prevent unauthorized data modification or access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle E-Business Suite
Oracle Human Resources