PT-2021-2818 · Oracle · Oracle E-Business Suite+2
Published
2021-04-22
·
Updated
2021-04-29
·
CVE-2021-2295
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Oracle E-Business Suite versions 12.1.3 and 12.2.3 through 12.2.10
Description:
The issue is related to inadequate access control in the BI Publisher Integration component of Oracle Concurrent Processing, allowing a low-privileged attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all accessible data, as well as unauthorized access to critical data.
Recommendations:
For versions 12.1.3, update to a version that includes the necessary security patches.
For versions 12.2.3 through 12.2.10, apply the recommended security fixes to mitigate the issue.
As a temporary workaround, consider restricting access to the BI Publisher Integration component until a patch is available.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bi Publisher Integration
Oracle Concurrent Processing
Oracle E-Business Suite