Vulnerability in Oracle Retail Customer Management Product by Oracle
CVE-2020-14732

3.1LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 October 2020

Summary

A vulnerability exists in the Oracle Retail Customer Management and Segmentation Foundation that allows a low-privileged attacker with network access to potentially gain unauthorized read access to sensitive data. The issue affects version 19.0 of the product and can be exploited via HTTP connections. This vulnerability may expose a subset of data to unauthorized individuals, resulting in potential information leakage. For detailed information, refer to the security alert issued by Oracle.

Affected Version(s)

Retail Customer Management and Segmentation Foundation 19.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.