Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-21136

Опубликовано: 16 июл. 2024
Источник: nvd
CVSS3: 8.6
EPSS Средний

Описание

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Office accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:oracle:retail_xstore_office:19.0.5:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_office:20.0.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_office:20.0.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_office:22.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_xstore_office:23.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.42062
Средний

8.6 High

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-200

Связанные уязвимости

CVSS3: 8.6
github
больше 1 года назад

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Office accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

CVSS3: 8.6
fstec
больше 1 года назад

Уязвимость компонента Security программного обеспечения для торговли Oracle Retail Xstore Office, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 97%
0.42062
Средний

8.6 High

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-200