Vulnerability in Oracle E-Business Suite Mobile Expenses Admin Utilities
CVE-2020-14720

7.7HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

A vulnerability exists in the Oracle Internet Expenses component of the Oracle E-Business Suite, specifically within the Mobile Expenses Admin Utilities. This issue is characterized by the potential for a low-privileged attacker with network access via HTTP to exploit the Oracle Internet Expenses system. While the vulnerability targets Oracle Internet Expenses directly, the ramifications can extend to other interconnected systems. Successful exploitation may lead to unauthorized access to sensitive data, compromising the security and confidentiality of information managed within the Oracle Internet Expenses platform.

Affected Version(s)

Internet Expenses 12.2.4-12.2.9

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.