CVE-2023-22042
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2023-22042 is a vulnerability affecting the Diagnostics component of Oracle E-Business Suite's Oracle Applications Framework, versions 12.2.3 to 12.3.12. This issue allows unauthenticated attackers with network access via HTTP to compromise the framework, potentially leading to unauthorized data updates, inserts, deletes, and reads. The vulnerability requires human interaction from a person other than the attacker. Though primarily impacting the Oracle Applications Framework, the scope may expand to additional products. The Base Score of this vulnerability, according to the Common Vulnerability Scoring System version 3.1, is 6.1 for both confidentiality and integrity impacts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Oracle Applications
Affected Vendors
- Oracle Corp