CVE-2024-21133 is a cross-site scripting (CWE-79) vulnerability affecting the Servlet component of Oracle Reports Developer versions 12.2.1.4.0 and 12.2.1.19.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Reports Developer, potentially leading to unauthorized read, update, insert, or delete access to accessible data. While successful attacks require user interaction, they can significantly impact additional products beyond Oracle Reports Developer itself, earning a CVSS 3.1 Base Score of 6.1 (Medium) due to low confidentiality and integrity impacts. There is currently no public exploit code (Metasploit, Nuclei, ExploitDB) available, and it is not known to be actively exploited, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2.1.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:reports_developer:12.2.1.4.0:*:*:*:*:*:*:* | ||
12.2.1.19.0CPE matchmatch criteria | cpe:2.3:a:oracle:reports_developer:12.2.1.19.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.