User Interface Vulnerability in Oracle Communications Diameter Signaling Router
CVE-2020-14787
5.4MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 21 October 2020
Summary
An exploitable user interface vulnerability exists in the Oracle Communications Diameter Signaling Router, allowing low-privileged attackers with network access via HTTP to compromise sensitive data. The vulnerability requires human interaction from a third party for successful exploitation. When exploited, attackers gain unauthorized access to the system, impacting confidentiality and integrity of the data managed by the Diameter Signaling Router, potentially leading to unauthorized updates, deletions, and readings of accessible data.
Affected Version(s)
Communications Diameter Signaling Router (DSR) 8.0.0.0-8.4.0.5
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved