User Interface Vulnerability in Oracle Communications Diameter Signaling Router
CVE-2020-14787

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 October 2020

Summary

An exploitable user interface vulnerability exists in the Oracle Communications Diameter Signaling Router, allowing low-privileged attackers with network access via HTTP to compromise sensitive data. The vulnerability requires human interaction from a third party for successful exploitation. When exploited, attackers gain unauthorized access to the system, impacting confidentiality and integrity of the data managed by the Diameter Signaling Router, potentially leading to unauthorized updates, deletions, and readings of accessible data.

Affected Version(s)

Communications Diameter Signaling Router (DSR) 8.0.0.0-8.4.0.5

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.