Unauthenticated Access Vulnerability in Oracle FLEXCUBE Direct Banking
CVE-2020-14897

6.5MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 October 2020

What is CVE-2020-14897?

The vulnerability in Oracle FLEXCUBE Direct Banking within Oracle Financial Services Applications allows an unauthenticated attacker to exploit network access via HTTP. Although successful exploitation relies on human interaction from a user other than the attacker, it poses significant risks by potentially granting unauthorized access to sensitive data. This issue affects multiple supported versions, with attackers being able to compromise the system and access critical data, ultimately leading to data breach incidents.

Affected Version(s)

FLEXCUBE Direct Banking 12.0.1

FLEXCUBE Direct Banking 12.0.2

FLEXCUBE Direct Banking 12.0.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-14897 : Unauthenticated Access Vulnerability in Oracle FLEXCUBE Direct Banking