SQL Extensions Vulnerability in Oracle E-Business Suite's Applications Manager
CVE-2020-14826
5.3MEDIUM
Summary
The vulnerability affects the Oracle Applications Manager component of Oracle E-Business Suite, specifically targeting SQL Extensions. This flaw allows an unauthenticated attacker with network access to exploit the system via HTTP. Successful exploitation could lead to unauthorized read access to certain data within the Oracle Applications Manager, raising concerns about data confidentiality. It primarily impacts versions 12.1.3 and 12.2.3 through 12.2.10, making it crucial for users to apply recommended security patches.
Affected Version(s)
Applications Manager 12.1.3
Applications Manager 12.2.3 - 12.2.10
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved