Unauthorized Access Vulnerability in Oracle E-Business Suite Marketing Administration
CVE-2020-14816

8.2HIGH

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
21 October 2020

Summary

The vulnerability exists within the Oracle Marketing product of Oracle E-Business Suite, specifically in the Marketing Administration component. It can be exploited by unauthenticated attackers who have network access through HTTP, facilitating unauthorized interactions that may lead to significant data breaches. Although the attack necessitates human interaction from a third party, successful exploitation could allow attackers to gain access to sensitive and confidential data or manipulate the data within Oracle Marketing. This could result in unauthorized updates, deletions, or insertions of records, raising serious concerns regarding data integrity and privacy.

Affected Version(s)

Marketing 12.1.1 - 12.1.3

Marketing 12.2.3 - 12.2.10

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.