Exploit in Oracle E-Business Suite's Application Object Library
CVE-2020-14554

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

A vulnerability exists in the Oracle Application Object Library component of Oracle E-Business Suite, affecting several versions including 12.1.3 and a range of 12.2 releases. This flaw allows an unauthenticated attacker to exploit the Application Object Library through network access via HTTP. While successful exploitation requires human interaction, the attack can lead to unauthorized access for updating, inserting, or deleting sensitive data managed by the library. Given the nature of the vulnerability, its repercussions could extend to adversely affecting other products within the Oracle ecosystem.

Affected Version(s)

Application Object Library 12.1.3

Application Object Library 12.2.3-12.2.8

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.