CVE-2021-2436 is a high-severity vulnerability affecting Oracle Common Applications within Oracle E-Business Suite versions 12.1.1-12.1.3 and 12.2.3-12.2.10, specifically in the CRM User Management Framework component. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise the application, requiring user interaction to succeed. Successful exploitation can lead to unauthorized access to critical data, complete access to all accessible data, and unauthorized modification of some data, resulting in a CVSS 3.1 Base Score of 8.2 (High). The attack vector is network-based with low attack complexity, but requires user interaction (UI:R) to be successful. While the vulnerability is in Oracle Common Applications, successful attacks may significantly impact additional products. The primary impacts are high confidentiality and low integrity, with no availability impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1.1, <= 12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:common_applications:*:*:*:*:*:*:*:* | ||
>= 12.2.3, <= 12.2.10CPE matchmatch criteria | cpe:2.3:a:oracle:common_applications:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.