CVE-2023-22004

Vulnerability in the Oracle Applications Technology product of Oracle E-Business Suite (component: Reports Configuration). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Technology accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).
References
Link Resource
https://www.oracle.com/security-alerts/cpujul2023.html Patch Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*

History

27 Jul 2023, 17:37

Type Values Removed Values Added
First Time Oracle e-business Suite
Oracle
CPE cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
References (MISC) https://www.oracle.com/security-alerts/cpujul2023.html - (MISC) https://www.oracle.com/security-alerts/cpujul2023.html - Patch, Vendor Advisory
CWE NVD-CWE-noinfo

18 Jul 2023, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-18 21:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-22004

Mitre link : CVE-2023-22004

CVE.ORG link : CVE-2023-22004


JSON object : View

Products Affected

oracle

  • e-business_suite