# N/A
## 漏洞概述
Oracle Retail Applications 产品中的 Oracle Retail Xstore Office 组件存在一个安全隐患,允许未经身份验证的攻击者通过网络访问(HTTP)进行攻击。成功利用此漏洞可导致未经授权访问关键数据或获取 Oracle Retail Xstore Office 存储的所有数据。
## 影响版本
- 19.0.5
- 20.0.3
- 20.0.4
- 22.0.0
- 23.0.1
## 漏洞细节
此漏洞易于利用,并允许未经身份验证的攻击者通过网络访问方式进行攻击,并利用漏洞访问 Oracle Retail Xstore Office 中的关键数据或所有可访问数据。虽然漏洞存在于 Oracle Retail Xstore Office 中,但攻击也可能对其他产品产生显著影响。
## 影响
此漏洞可能带来的影响包括未经授权访问敏感数据或获取 Oracle Retail Xstore Office 存储的所有数据。根据 CVSS 3.1 基础分数 8.6,此漏洞将导致数据的机密性受损。CVSS 向量为 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change). | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-21136.yaml | POC详情 |
标题: Oracle Critical Patch Update Advisory - July 2024 -- 🔗来源链接
标签: vendor-advisory