Unauthorized Access Vulnerability in Oracle Commerce Platform by Oracle
CVE-2020-14533
3.5LOW
What is CVE-2020-14533?
A vulnerability exists within the Oracle Commerce Platform's Dynamo Application Framework, potentially allowing a high-privileged attacker with network access via HTTP to exploit the platform. The attack requires human interaction from a third party, leading to unauthorized update, insertion, or deletion of accessible data. Furthermore, it provides access to confidential data, risking integrity and confidentiality within supported versions 11.1, 11.2, and those prior to 11.3.1.
Affected Version(s)
Commerce Platform 11.1
Commerce Platform 11.2
Commerce Platform < 11.3.1