Vulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions that are affected are Application Express Team Calendar Plugin: 18.2-22.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Application Express Team Calendar Plugin. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Application Express Team Calendar Plugin, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Application Express Team Calendar Plugin. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published: 2023-07-18T20:18:02.290Z

Updated: 2024-09-13T17:53:23.321Z

Reserved: 2022-12-17T19:26:00.736Z

Link: CVE-2023-21974

cve-icon Vulnrichment

Updated: 2024-08-02T09:59:28.674Z

cve-icon NVD

Status : Analyzed

Published: 2023-07-18T21:15:11.597

Modified: 2023-07-27T17:38:13.767

Link: CVE-2023-21974

cve-icon Redhat

No data.