Unauthenticated Access Vulnerability in Oracle CRM Technical Foundation
CVE-2020-14660

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

The vulnerability in Oracle CRM Technical Foundation allows an unauthenticated attacker with network access via HTTP to exploit the system. Successful exploitation could enable unauthorized access to sensitive data and permit attackers to claim complete control over all accessible information. The attacks necessitate human interaction from another individual, amplifying the risk as various Oracle products may experience significant impacts due to this vulnerability. Attackers may gain the ability to update, insert, or delete critical data, compromising both confidentiality and integrity.

Affected Version(s)

CRM Technical Foundation 12.1.3

CRM Technical Foundation 12.2.3-12.2.9

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.