Vulnerability in Oracle FLEXCUBE Direct Banking Affects Multiple Versions
CVE-2020-14890

6.5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 October 2020

Summary

A vulnerability exists in the Oracle FLEXCUBE Direct Banking product that allows an unauthenticated attacker with network access via HTTP to compromise the system. This flaw affects supported versions 12.0.1, 12.0.2, and 12.0.3. While successful exploitation requires human interaction from a user other than the attacker, it can lead to unauthorized access to sensitive data, potentially exposing critical information within the FLEXCUBE Direct Banking environment.

Affected Version(s)

FLEXCUBE Direct Banking 12.0.1

FLEXCUBE Direct Banking 12.0.2

FLEXCUBE Direct Banking 12.0.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.