PT-2024-4902 · Oracle · Oracle Production Scheduling

Published

2024-04-16

·

Updated

2024-11-15

·

CVE-2024-21088

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions: Oracle Production Scheduling versions 12.2.4 through 12.2.12
Description: The issue exists due to insufficient input validation in the Import Utility component of Oracle Production Scheduling in Oracle E-Business Suite. This allows a remote attacker to modify, add, or delete data. Successful attacks can result in unauthorized access to critical data or all accessible data in Oracle Production Scheduling.
Recommendations: For versions 12.2.4 through 12.2.12, update to a version that includes the fix for this issue to prevent unauthorized data modification. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

BDU:2024-05426
CVE-2024-21088

Affected Products

Oracle Production Scheduling