cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2023-21973,https://securityvulnerability.io/vulnerability/CVE-2023-21973,Vulnerability in Oracle iProcurement of Oracle E-Business Suite,"A vulnerability exists in Oracle iProcurement within the Oracle E-Business Suite's E-Content Manager Catalog component. This flaw allows a low-privileged attacker with network access via HTTP to compromise the system. Although reliance on human interaction from an external party is required for exploitation, successful attacks can lead to unauthorized updates, insertions, or deletions of data within Oracle iProcurement. Furthermore, attackers may gain unauthorized read access to certain datasets. The potential for these attacks could extend beyond just Oracle iProcurement, affecting other products and increasing the breadth of the attack's impact.",Oracle,Iprocurement,5.4,MEDIUM,0.00044999999227002263,false,,false,false,false,,,false,false,,2023-04-18T20:15:00.000Z,0 CVE-2018-3151,https://securityvulnerability.io/vulnerability/CVE-2018-3151,,"Vulnerability in the Oracle iProcurement component of Oracle E-Business Suite (subcomponent: E-Content Manager Catalog). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iProcurement. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iProcurement accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",Oracle,Iprocurement,7.5,HIGH,0.001500000013038516,false,,false,false,false,,,false,false,,2018-10-17T01:00:00.000Z,0 CVE-2016-5562,https://securityvulnerability.io/vulnerability/CVE-2016-5562,,Unspecified vulnerability in the Oracle iProcurement component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.,Oracle,Iprocurement,7.6,HIGH,0.0009200000204145908,false,,false,false,false,,,false,false,,2016-10-25T14:00:00.000Z,0