PT-2023-3627 · Oracle · Application Express Customers Plugin

Kanika Jalal

+1

·

Published

2023-07-18

·

Updated

2023-07-27

·

CVE-2023-21975

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Application Express Customers Plugin versions 18.2 through 22.2
Description The issue exists due to insufficient input validation in the Application Express Customers Plugin component of Oracle Application Express. This allows a remote attacker to modify, add, or delete data using the HTTP protocol. Successful attacks require human interaction and may significantly impact additional products. The vulnerability can result in the takeover of the Application Express Customers Plugin.
Recommendations For versions 18.2 through 22.2, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-03911
CVE-2023-21975

Affected Products

Application Express Customers Plugin