Vulnerability in Oracle Commerce Platform's Dynamo Application Framework
CVE-2020-14532
4.7MEDIUM
Summary
A vulnerability exists within the Oracle Commerce Platform's Dynamo Application Framework, allowing unauthenticated attackers to gain network access via HTTP. This can result in unauthorized updates, insertions, or deletions of accessible data, especially with human interaction required from an unsuspecting user. Although the primary issue is in the Oracle Commerce Platform, the implications of a successful attack may extend to other associated products.
Affected Version(s)
Commerce Platform 11.1
Commerce Platform 11.2
Commerce Platform < 11.3.1
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved