Unauthenticated Denial of Service in Oracle Financial Services Analytical Applications
CVE-2020-14824

8.6HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 October 2020

Summary

The vulnerability in Oracle Financial Services Analytical Applications Infrastructure allows an unauthenticated attacker to compromise the system via HTTP requests, potentially causing a denial of service. Affected installations running version 8.0.6 through 8.1.0 can be disrupted, leading to significant operational impacts including system hangs or repeated crashes. While primarily impacting the Infrastructure component, exploitation may also affect other linked applications.

Affected Version(s)

Financial Services Analytical Applications Infrastructure 8.0.6-8.1.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.