Vulnerability in Oracle Business Intelligence Enterprise Edition by Oracle Fusion Middleware
CVE-2020-14548

3.4LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

A vulnerability exists in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware that enables unauthenticated attackers with HTTP network access to potentially compromise the system. While the attack requires some human interaction from an external individual, the successful exploitation can lead to unauthorized access to certain confidential data. This situation presents a significant risk, as the impact may extend beyond the primary product and affect other integrated services.

Affected Version(s)

Oracle Business Intelligence Enterprise Edition 12.2.1.3.0

Oracle Business Intelligence Enterprise Edition 12.2.1.4.0

References

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.