Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-21146

CVE-2024-21146: Oracle Trade Management Auth Bypass Flaw

CVE-2024-21146 is an authentication bypass vulnerability in Oracle Trade Management that enables low-privileged attackers to access and modify critical data. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2024-21146 Overview

CVE-2024-21146 is a high-severity vulnerability in the Oracle Trade Management product of Oracle E-Business Suite, specifically within the GL Accounts component. The flaw affects supported versions 12.2.3 through 12.2.13. A low-privileged attacker with network access via HTTP can exploit this vulnerability without user interaction. Successful exploitation permits unauthorized creation, deletion, or modification of critical data, along with unauthorized read access to all Oracle Trade Management accessible data. The weakness maps to [CWE-306: Missing Authentication for Critical Function].

Critical Impact

Remote attackers with only low-level privileges can compromise the confidentiality and integrity of all data accessible through Oracle Trade Management over HTTP.

Affected Products

  • Oracle E-Business Suite - Oracle Trade Management 12.2.3
  • Oracle E-Business Suite - Oracle Trade Management 12.2.4 through 12.2.12
  • Oracle E-Business Suite - Oracle Trade Management 12.2.13

Discovery Timeline

  • 2024-07-16 - CVE-2024-21146 published to NVD as part of the Oracle Critical Patch Update July 2024
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-21146

Vulnerability Analysis

CVE-2024-21146 resides in the GL Accounts component of Oracle Trade Management, part of the broader Oracle E-Business Suite. The flaw allows a network-based attacker holding a low-privileged authenticated session to reach functionality that lacks proper authentication or authorization enforcement. Once exploited, the attacker gains read and write access to critical Trade Management data, including general ledger account records used for marketing budgets, claims, and settlements.

Because Trade Management integrates with financial modules across E-Business Suite, tampering with GL Accounts data can cascade into downstream financial reporting and reconciliation processes. Availability is not impacted, but confidentiality and integrity are fully compromised within the Trade Management scope.

Root Cause

The root cause is a missing authentication check on a critical function within the GL Accounts component ([CWE-306]). The affected code path exposes data operations over HTTP without verifying that the requester holds the entitlements required to perform them. Any authenticated E-Business Suite user with minimal privileges can invoke the operation.

Attack Vector

Exploitation occurs over the network via HTTP against an exposed Oracle E-Business Suite deployment. The attacker requires a valid low-privileged account, no user interaction, and low attack complexity. The attacker sends crafted HTTP requests to the vulnerable Trade Management endpoints to read, create, modify, or delete GL Accounts records. No verified public proof-of-concept is available at the time of writing.

Refer to the Oracle Critical Patch Update Advisory - July 2024 for authoritative technical detail.

Detection Methods for CVE-2024-21146

Indicators of Compromise

  • Unexpected HTTP requests targeting Oracle Trade Management GL Accounts URLs from user accounts that do not normally interact with Trade Management.
  • Unauthorized create, update, or delete operations against GL Accounts records outside of scheduled business processes.
  • Anomalous spikes in Trade Management audit log entries originating from low-privileged E-Business Suite accounts.

Detection Strategies

  • Enable and review Oracle E-Business Suite Sign-On Audit and page access tracking to correlate GL Accounts access with user role assignments.
  • Alert on HTTP requests to Trade Management endpoints that return successful responses for users lacking the corresponding Trade Management responsibility.
  • Compare database-level changes to ozf_* and general ledger tables against expected application workflows.

Monitoring Recommendations

  • Forward Oracle E-Business Suite application, database, and web tier logs to a centralized analytics platform for cross-source correlation.
  • Baseline normal Trade Management usage per user and role, then alert on deviations such as off-hours access or unusual request volumes.
  • Monitor privileged and service accounts for lateral movement into Trade Management functions they do not require.

How to Mitigate CVE-2024-21146

Immediate Actions Required

  • Apply the Oracle Critical Patch Update from July 2024 to all Oracle E-Business Suite environments running Trade Management versions 12.2.3 through 12.2.13.
  • Restrict network exposure of the E-Business Suite web tier to trusted networks and authenticated users only.
  • Review Trade Management responsibility assignments and revoke access for accounts that do not require it.

Patch Information

Oracle addressed CVE-2024-21146 in the Oracle Critical Patch Update Advisory - July 2024. Administrators should follow Oracle's documented patch application procedure for E-Business Suite 12.2, including running adop to apply the patch and validating the environment post-deployment.

Workarounds

  • Place the Oracle E-Business Suite web tier behind a reverse proxy or web application firewall that enforces authentication and restricts Trade Management URLs to authorized users.
  • Disable or restrict access to the Trade Management responsibility for users who do not require GL Accounts functionality until the patch is deployed.
  • Increase audit logging on Trade Management and related financial modules to shorten detection time while patching is in progress.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.