Unauthenticated Access Vulnerability in Oracle Marketing Product by Oracle
CVE-2020-14849
Summary
A vulnerability exists in the Marketing Administration component of the Oracle Marketing product within Oracle E-Business Suite. This flaw allows unauthenticated attackers with network access to exploit the vulnerability via HTTP. Successful exploitation necessitates human interaction from a victim, which can lead to unauthorized access to sensitive data within Oracle Marketing. The impact extends beyond the Marketing product, potentially compromising additional components within the Oracle E-Business Suite. Attackers could gain extensive access rights, enabling them to update, insert, or delete data, which raises serious concerns regarding data confidentiality and integrity.
Affected Version(s)
Marketing 12.1.1 - 12.1.3
Marketing 12.2.3 - 12.2.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved