Oracle E-Business Suite Vulnerability in Universal Work Queue
CVE-2020-14862
8.8HIGH
Summary
The Oracle Universal Work Queue component within Oracle E-Business Suite is susceptible to an access control vulnerability that can be exploited by low privileged attackers with network access via HTTP. This easily exploitable flaw permits unauthorized access, potentially leading to a complete takeover of the Oracle Universal Work Queue. This vulnerability affects Oracle E-Business Suite versions 12.2.3 to 12.2.9, posing a significant risk to organizations depending on this system for their operations.
Affected Version(s)
Universal Work Queue 12.2.3 - 12.2.9
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved