CVE-2024-21261

Vulnerability in Oracle Application Express (component: General). Supported versions that are affected are 23.2 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. While the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N).
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:application_express:23.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:application_express:24.1:*:*:*:*:*:*:*

History

21 Oct 2024, 18:27

Type Values Removed Values Added
References () https://www.oracle.com/security-alerts/cpuoct2024.html - () https://www.oracle.com/security-alerts/cpuoct2024.html - Vendor Advisory
First Time Oracle application Express
Oracle
CPE cpe:2.3:a:oracle:application_express:23.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:application_express:24.1:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo

16 Oct 2024, 16:38

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad en Oracle Application Express (componente: General). Las versiones compatibles afectadas son 23.2 y 24.1. Esta vulnerabilidad, difícil de explotar, permite que un atacante con privilegios reducidos y acceso a la red a través de HTTP ponga en peligro Oracle Application Express. Si bien la vulnerabilidad se encuentra en Oracle Application Express, los ataques pueden afectar significativamente a otros productos (cambio de alcance). Los ataques exitosos de esta vulnerabilidad pueden dar como resultado la actualización, inserción o eliminación no autorizada de algunos datos accesibles de Oracle Application Express, así como el acceso de lectura no autorizado a un subconjunto de datos accesibles de Oracle Application Express. Puntuación base de CVSS 3.1: 4,9 (impactos en la confidencialidad y la integridad). Vector CVSS: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N).

15 Oct 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-15 20:15

Updated : 2024-10-21 18:27


NVD link : CVE-2024-21261

Mitre link : CVE-2024-21261

CVE.ORG link : CVE-2024-21261


JSON object : View

Products Affected

oracle

  • application_express