Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-21100


Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. While the vulnerability is in Oracle Commerce Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 4.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N).


Published

2024-04-16T22:15:30.903

Last Modified

2024-12-06T21:24:25.520

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.0 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oracle commerce_platform 11.3.0 Yes
Application oracle commerce_platform 11.3.1 Yes
Application oracle commerce_platform 11.3.2 Yes

References