CVE-2024-21081 is a vulnerability in Oracle Partner Management, specifically affecting versions 12.2.3 through 12.2.13 of Oracle E-Business Suite. This easily exploitable vulnerability allows an unauthenticated attacker to compromise Oracle Partner Management via HTTP, requiring user interaction and potentially impacting additional products. With a CVSS 3.1 Base Score of 4.7 (Medium), successful attacks can lead to unauthorized modification of Oracle Partner Management data. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.3, <= 12.2.13CPE match | cpe:2.3:a:oracle:partner_management:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.