CVE-2026-21972 - Vulnerability in the Oracle Configurator product o

CVE-2026-21972 - Vulnerability in the Oracle Configurator product o

CVE ID : CVE-2026-21972 Published : Jan. 20, 2026, 10:16 p.m. | 43 minutes ago Description : Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Configurator accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
CVSS Score
3.1 / 10.0
Published
Jan. 20, 2026
Affected Product: Oracle Configurator
Attack Vector: network
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C