Vulnerability in Oracle E-Business Suite Preferences Component
CVE-2020-14659

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

A vulnerability exists within the Preferences component of Oracle CRM Technical Foundation in the Oracle E-Business Suite that allows unauthenticated attackers with network access via HTTP to execute unauthorized operations, such as updating, inserting, or deleting data. Exploiting this vulnerability necessitates human interaction, making it particularly concerning as it can impact other related products. If successfully exploited, attackers may gain access to sensitive information within the affected application.

Affected Version(s)

CRM Technical Foundation 12.1.3

CRM Technical Foundation 12.2.3-12.2.9

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.