PT-2022-4683 · Oracle · Oracle Financial Services Revenue Management/Billing

Published

2022-07-19

·

Updated

2022-07-26

·

CVE-2022-21580

CVSS v2.0

6.1

Medium

VectorAV:N/AC:H/Au:S/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Financial Services Revenue Management and Billing versions 2.9.0.0.0 through 2.9.0.1.0 Oracle Financial Services Revenue Management and Billing versions 3.0.0.0.0 through 3.2.0.0.0 Oracle Financial Services Revenue Management and Billing version 4.0.0.0.0
Description The issue allows a low-privileged attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing, requiring human interaction from a person other than the attacker. Successful attacks can result in unauthorized access to critical data, complete access to all accessible data, unauthorized update, insert, or delete access to some accessible data, and the ability to cause a partial denial of service.
Recommendations For versions 2.9.0.0.0 through 2.9.0.1.0, update to a version that is not affected by this issue. For versions 3.0.0.0.0 through 3.2.0.0.0, update to a version that is not affected by this issue. For version 4.0.0.0.0, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the vulnerable component until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05573
CVE-2022-21580

Affected Products

Oracle Financial Services Revenue Management/Billing