Cyber Resilience

CVE-2023-22042

Oracle Applications Framework 12.2.3 – 12.3.12

Published
18 July 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score 0.0042 35th percentile
Risk Priority 46 floored blend · peak EPSS

Summary

CVE-2023-22042 is a medium-severity an unspecified weakness vulnerability in Oracle Applications Framework. Its CVSS base score is 6.1 (Medium).

Operationally, ranked at the 35th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.3-12.3.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human…

more

interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-60684Same product: Oracle Applications Framework
CVE-2026-60774Same product: Oracle Applications Framework
CVE-2025-53064Same product: Oracle Applications Framework
CVE-2026-60768Same product: Oracle Applications Framework
CVE-2026-62546Same product: Oracle Applications Framework
CVE-2026-34298Same product: Oracle Applications Framework
CVE-2025-30711Same product: Oracle Applications Framework
CVE-2026-60676Same product: Oracle Applications Framework
CVE-2026-60675Same product: Oracle Applications Framework
CVE-2026-62534Same product: Oracle Applications Framework

Affected Assets

oracle
applications framework
12.2.3 — 12.3.12

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References