Unauthenticated Access Vulnerability in Oracle Trade Management by Oracle
CVE-2020-14808
8.2HIGH
Summary
A vulnerability exists in Oracle Trade Management, part of the Oracle E-Business Suite, that permits unauthenticated attackers with network access via HTTP to access sensitive data. This vulnerability can lead to unauthorized access and potential alteration of critical information within the Oracle Trade Management system. Successful exploitation requires human interaction from a third party, emphasizing the need for enhanced security measures. The impact of attacks could extend beyond the affected product, potentially compromising additional components of the Oracle E-Business Suite.
Affected Version(s)
Trade Management 12.1.3
Trade Management 12.2.3 - 12.2.10
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved