Unauthenticated Denial of Service in Oracle Financial Services Analytical Applications
CVE-2020-14824
8.6HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 21 October 2020
Summary
The vulnerability in Oracle Financial Services Analytical Applications Infrastructure allows an unauthenticated attacker to compromise the system via HTTP requests, potentially causing a denial of service. Affected installations running version 8.0.6 through 8.1.0 can be disrupted, leading to significant operational impacts including system hangs or repeated crashes. While primarily impacting the Infrastructure component, exploitation may also affect other linked applications.
Affected Version(s)
Financial Services Analytical Applications Infrastructure 8.0.6-8.1.0
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved