Vulnerability in Oracle E-Business Suite's CRM Gateway for Mobile Devices
CVE-2020-14599

9.1CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

An unauthenticated network access vulnerability exists in the Setup of Mobile Applications component of Oracle's CRM Gateway for Mobile Devices, which may allow an attacker to exploit the system without authentication. Successful exploitation can lead to unauthorized creation, deletion, or modification of access to sensitive data within the Oracle CRM Gateway, raising significant concerns around data integrity and confidentiality. This vulnerability highlights the necessity for organizations to secure their mobile applications against potential threats.

Affected Version(s)

CRM Gateway for Mobile Devices 12.1.1-12.1.3

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.