Vulnerability in Oracle Database Server Group Calendar Component
CVE-2020-14900
5.4MEDIUM
What is CVE-2020-14900?
A vulnerability exists in the Oracle Application Express Group Calendar component of Oracle Database Server that allows a low privileged attacker with a valid user account to exploit the system via HTTP. Successful exploitation of this vulnerability requires interaction from a user other than the attacker, potentially leading to unauthorized updates, insertions, or deletions of accessible data within the Group Calendar. Moreover, it can also grant unauthorized read access to a portion of the data, affecting not only the Group Calendar component but potentially impacting additional connected products.
Affected Version(s)
Application Express (APEX) < 20.2