CVE-2021-35689
A potential vulnerability in the Oracle Talent Acquisition Cloud - Taleo Enterprise Edition.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A potential vulnerability in the Oracle Talent Acquisition Cloud - Taleo Enterprise Edition. This high severity potential vulnerability allows attackers to perform remote code execution on Taleo Enterprise Edition system. Successful attacks of this vulnerability can result in unauthorized remote code execution within Taleo Enterprise Edition and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Talent Acquisition Cloud - Taleo Enterprise Edition. All affected customers were notified of CVE-2021-35689 by Oracle.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.12% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- oracle/talent acquisition cloud
- Source
- secalert_us@oracle.com
References
- https://www.oracle.com/security-alerts/oracle-cves-outside-other-oracle-public-documents.htmlPermissions Required, Vendor Advisory
- https://www.oracle.com/security-alerts/oracle-cves-outside-other-oracle-public-documents.htmlPermissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.