CVE-2024-21078Active Exploitation(oracle / marketing)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch oracle marketing systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Campaign LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

4.0/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • marketing

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
marketing

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-29: 1Active Exploitation · 2026-06-29: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-29: 106-29
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • CiberBaur@BotBauR
    Active Exploitation

    Acaba de confirmarse: hackers están explotando una vulnerabilidad crítica en Oracle E-Business Suite (EBS), específicamente en el módulo Oracle Marketing, identificada como CVE-2024-21078. La empresa afectada es Oracle, y la vulnerabilidad impacta a versiones 12.2.3 a 12.2.13 de Oracle Marketing dentro de E-Business Suite. El tipo de fallo es exposición de información en el componente Campaign LOV, sin requerir autenticación ni interacción del usuario. La explotación de esta vulnerabilidad puede comprometer la confidencialidad de los datos accesibles por el módulo Oracle Marketing, aunque Oracle indica que no hay impacto directo en integridad o disponibilidad. El vector típico de ataque involucra peticiones HTTP especialmente construidas contra endpoints de Campaign LOV. El impacto es significativo, ya que puede exponer datos sensibles a gran escala. Aunque no hay cifras concretas de registros expuestos o dinero robado, la gravedad de la vulnerabilidad y su explotación activa por parte de hackers hacen que sea crucial tomar medidas de seguridad. Hay un parche disponible para esta vulnerabilidad. Los afectados deben aplicar el parche lo antes posible y revisar los logs de seguridad para detectar cualquier actividad sospechosa. ¿Estás en riesgo? Revisa esto: asegúrate de tener actualizado tu sistema Oracle E-Business Suite y aplica el parche correspondiente. #Ciberseguridad #CVE #SeguridadDigital #PYMEsMX https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/

    Post summary

    The post confirms attackers are actively exploiting CVE‑2024‑21078 against Oracle E‑Business Suite’s Marketing module, providing specific technical details and noting that a patch is available.

    01022145
    616 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclemarketing---

Explore more