Unauthenticated Access Vulnerability in Oracle E-Business Suite CRM User Management
CVE-2020-14717
4.7MEDIUM
Summary
A vulnerability exists in the Oracle Common Applications of Oracle E-Business Suite, specifically within the CRM User Management Framework. This issue allows an unauthenticated attacker with network access via HTTP to exploit the framework, leading to important security ramifications. Successful exploitation requires interaction from a third party, but once achieved, can allow for unauthorized updates, inserts, or deletions of accessible data. This vulnerability primarily affects versions 12.1.3 and 12.2.3 through 12.2.9, posing a risk to organizations relying on these applications.
Affected Version(s)
Common Applications 12.1.3
Common Applications 12.2.3-12.2.9
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved