Unauthorized Data Access Vulnerability in Oracle Marketing by Oracle
CVE-2020-14555
4.7MEDIUM
Summary
An unauthenticated attacker with network access via HTTP can exploit the vulnerability residing in Oracle Marketing within Oracle E-Business Suite. Affected versions range from 12.1.1 to 12.1.3 and 12.2.3 to 12.2.9. The successful exploitation requires human interaction from a secondary user and can lead to unauthorized update, insertion, or deletion of data within Oracle Marketing. Additionally, while the vulnerability itself is localized within Oracle Marketing, the implications of successful attacks may extend to other connected products, potentially compromising further data integrity.
Affected Version(s)
Marketing 12.1.1-12.1.3
Marketing 12.2.3-12.2.9
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved