Cyber Resilience

CVE-2023-21994

Oracle Fusion Middleware ≤ 11.1.2.3.1

Published
18 July 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0041 34th percentile
Risk Priority 50 floored blend · peak EPSS

Summary

CVE-2023-21994 is a medium-severity an unspecified weakness vulnerability in Oracle Fusion Middleware. Its CVSS base score is 6.5 (Medium).

Operationally, ranked at the 34th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Vulnerability in the Oracle Mobile Security Suite product of Oracle Fusion Middleware (component: Android Mobile Authenticator App). Supported versions that are affected are Prior to 11.1.2.3.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached…

more

to the hardware where the Oracle Mobile Security Suite executes to compromise Oracle Mobile Security Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Mobile Security Suite accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CWE(s)

Related Threats

CVEs Like This One

CVE-2012-3152Same product: Oracle Fusion Middleware
CVE-2024-21192Same product: Oracle Fusion Middleware
CVE-2012-0518Same product: Oracle Fusion Middleware
CVE-2024-21215Same product: Oracle Fusion Middleware
CVE-2024-21205Same product: Oracle Fusion Middleware
CVE-2012-1710Same product: Oracle Fusion Middleware
CVE-2026-35232Same product: Oracle Fusion Middleware
CVE-2024-21191Same product: Oracle Fusion Middleware
CVE-2024-21190Same product: Oracle Fusion Middleware
CVE-2026-35252Same product: Oracle Fusion Middleware

Affected Assets

oracle
fusion middleware
≤ 11.1.2.3.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References