Vulnerability in User Interface of Oracle E-Business Suite Trade Management
CVE-2020-14876
9.1CRITICAL
Summary
The vulnerability in the User Interface component of Oracle Trade Management within the Oracle E-Business Suite allows an unauthenticated attacker with network access to exploit the system through HTTP. This flaw enables unauthorized actions such as the creation, deletion, or modification of critical data. Successful exploitation can lead to complete control over all accessible data within Oracle Trade Management, jeopardizing the confidentiality and integrity of sensitive information. Organizations using affected versions (12.1.1 - 12.1.3 and 12.2.3 - 12.2.10) should prioritize remediation measures to protect their systems.
Affected Version(s)
Trade Management 12.1.1 - 12.1.3
Trade Management 12.2.3 - 12.2.10
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved