Exploitable Data Modification Flaw in Oracle Financial Services Applications
CVE-2020-14685

6.5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

A vulnerability exists within the Oracle Financial Services Analytical Applications Infrastructure, enabling low privileged attackers with network access via HTTP to exploit the system. This vulnerability allows unauthorized users to create, delete, or modify critical data stored within the applications. With supported versions ranging from 8.0.6 to 8.1.0, effective exploitation can compromise the integrity of significant data, posing serious security risks to organizational operations.

Affected Version(s)

Financial Services Analytical Applications Infrastructure 8.0.6-8.1.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.