Unauthenticated Access Vulnerability in Oracle E-Business Suite's Applications Manager
CVE-2020-14811
5.3MEDIUM
Summary
A vulnerability exists in Oracle Applications Manager, part of the Oracle E-Business Suite, that could allow an unauthenticated attacker with network access to HTTP to gain unauthorized read access to sensitive data. This issue particularly affects the supported versions 12.1.3 and 12.2.3 through 12.2.10. If exploited, the attacker could compromise the integrity of the data managed by Oracle Applications Manager, leading to potential data breaches.
Affected Version(s)
Applications Manager 12.1.3
Applications Manager 12.2.3 - 12.2.10
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved