Security Vulnerability in Oracle Retail Customer Management Product
CVE-2020-14710
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 15 July 2020
Summary
The Customer Management and Segmentation Foundation product within Oracle Retail Applications has a vulnerability allowing attackers with low privilege and network access via HTTP to compromise its security. This easily exploitable vulnerability can lead to unauthorized updates, inserts, or deletions of accessible data, as well as unauthorized read access to certain data sets. Organizations using affected versions (16.0, 17.0, and 18.0) should take immediate action to mitigate potential risks to their data integrity and confidentiality.
Affected Version(s)
Retail Customer Management and Segmentation Foundation 16.0
Retail Customer Management and Segmentation Foundation 17.0
Retail Customer Management and Segmentation Foundation 18.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved