Vulnerability in Oracle Cloud Infrastructure Identity and Access Management
CVE-2020-14874

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 December 2020

Summary

A vulnerability exists within Oracle Cloud Infrastructure Identity and Access Management that can be exploited by a high privileged attacker with network access. This flaw allows for unauthorized updates, insertions, or deletions of accessible data. Additionally, it can lead to unauthorized read access to certain data and the ability to partially disrupt services, resulting in a significant risk to cloud service integrity and availability.

Affected Version(s)

Oracle Cloud Infrastructure Identity and Access Management *

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.