CVE-2024-20942
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-20942 is a vulnerability affecting Oracle Complex Maintenance, Repair, and Overhaul, a component of Oracle Supply Chain. Versions 11.5, 12.1, and 12.2 are susceptible to this easily exploitable issue. An unauthenticated attacker with network access via HTTP can exploit it to compromise the Oracle Complex Maintenance, Repair, and Overhaul product. Human interaction is required for a successful attack, and the vulnerability could potentially impact additional products as well. Successful exploitation may result in unauthorized update, insert, or delete access to certain data, as well as unauthorized read access to a subset of data. The CVSS Base Score is 6.1, with Confidentiality and Integrity impacts. (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Oracle Complex Maintenance, Repair, And Overhaul
Affected Vendors
- BonqDAO