Unauthorized Access Vulnerability in Oracle E-Business Suite's Universal Work Queue
CVE-2020-14855

9.8CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 October 2020

Summary

A vulnerability exists in Oracle E-Business Suite's Universal Work Queue component, allowing an unauthenticated attacker with network access over HTTP to compromise its functionality. This breach could lead to unauthorized control over the Universal Work Queue, posing significant risks to confidentiality, integrity, and availability of system resources.

Affected Version(s)

Universal Work Queue 12.1.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.