PT-2024-7259 · Oracle · Enterprise Manager For Fusion Middleware+1

Published

2024-10-15

·

Updated

2024-10-18

·

CVE-2024-21192

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Enterprise Manager for Fusion Middleware version 12.2.1.4.0
Description The issue is related to insufficient input validation in the WebLogic Mgmt component of Oracle Enterprise Manager for Fusion Middleware. This can allow an attacker to disclose protected information. Successful attacks can result in unauthorized access to critical data or complete access to all accessible data.
Recommendations For version 12.2.1.4.0, upgrade the affected component to mitigate the risk. As a temporary workaround, consider restricting access to the WebLogic Mgmt component until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-08607
CVE-2024-21192

Affected Products

Enterprise Manager For Fusion Middleware
Weblogic