Vulnerability in Oracle Database Server Group Calendar Component
CVE-2020-14900
5.4MEDIUM
Summary
A vulnerability exists in the Oracle Application Express Group Calendar component of Oracle Database Server that allows a low privileged attacker with a valid user account to exploit the system via HTTP. Successful exploitation of this vulnerability requires interaction from a user other than the attacker, potentially leading to unauthorized updates, insertions, or deletions of accessible data within the Group Calendar. Moreover, it can also grant unauthorized read access to a portion of the data, affecting not only the Group Calendar component but potentially impacting additional connected products.
Affected Version(s)
Application Express (APEX) < 20.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved