Cyber Resilience

CVE-2023-21978

Oracle Application Object Library 12.2.3 – 12.2.11

Published
18 April 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0038 31th percentile
Risk Priority 47 floored blend · peak EPSS

Summary

CVE-2023-21978 is a medium-severity an unspecified weakness vulnerability in Oracle Application Object Library. Its CVSS base score is 6.5 (Medium).

Operationally, ranked at the 31th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: GUI). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful…

more

attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data as well as unauthorized read access to a subset of Oracle Application Object Library accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Object Library. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L).

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-61116Same product: Oracle Application Object Library
CVE-2024-21128Same product: Oracle Application Object Library
CVE-2026-60770Same product: Oracle Application Object Library
CVE-2025-30726Same product: Oracle Application Object Library
CVE-2026-60773Same product: Oracle Application Object Library
CVE-2025-30732Same product: Oracle Application Object Library
CVE-2026-60776Same product: Oracle Application Object Library
CVE-2024-20915Same product: Oracle Application Object Library
CVE-2024-20929Same product: Oracle Application Object Library
CVE-2026-60154Same product: Oracle Application Object Library

Affected Assets

oracle
application object library
12.2.3 — 12.2.11

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References