PT-2022-4683 · Oracle · Oracle Financial Services Revenue Management/Billing
Published
2022-07-19
·
Updated
2022-07-26
·
CVE-2022-21580
CVSS v2.0
6.1
Medium
| Vector | AV:N/AC:H/Au:S/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Financial Services Revenue Management and Billing versions 2.9.0.0.0 through 2.9.0.1.0
Oracle Financial Services Revenue Management and Billing versions 3.0.0.0.0 through 3.2.0.0.0
Oracle Financial Services Revenue Management and Billing version 4.0.0.0.0
Description
The issue allows a low-privileged attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing, requiring human interaction from a person other than the attacker. Successful attacks can result in unauthorized access to critical data, complete access to all accessible data, unauthorized update, insert, or delete access to some accessible data, and the ability to cause a partial denial of service.
Recommendations
For versions 2.9.0.0.0 through 2.9.0.1.0, update to a version that is not affected by this issue.
For versions 3.0.0.0.0 through 3.2.0.0.0, update to a version that is not affected by this issue.
For version 4.0.0.0.0, update to a version that is not affected by this issue.
As a temporary workaround, consider restricting access to the vulnerable component until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Financial Services Revenue Management/Billing