CVE-2024-21076 is an easily exploitable vulnerability in the Offer LOV component of Oracle Trade Management, affecting versions 12.2.3 through 12.2.13 of Oracle E-Business Suite. This unauthenticated vulnerability, accessible via HTTP, carries a CVSS 3.1 Base Score of 7.5 (High) due to its potential for unauthorized access to critical or all accessible data within Oracle Trade Management. While the EPSS score is low and there are no known public exploits, Metasploit modules, or community discussions, organizations should still prioritize patching due to the significant confidentiality impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.3, <= 12.2.13CPE match | cpe:2.3:a:oracle:trade_management:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.