SQL Injection Vulnerability in Oracle Application Express Component of Oracle Database Server
CVE-2020-2513
5.4MEDIUM
Summary
A vulnerability exists in Oracle Application Express, part of the Oracle Database Server, that can be exploited by a low privileged attacker with network access via HTTP. The attacker must engage a third party to facilitate the attack, allowing unauthorized access to update, insert, or delete data within Oracle Application Express. Furthermore, attackers may gain unauthorized read access to certain data, potentially impacting other connected products. The affected versions range from 5.1 to 19.2, and organizations using these versions are advised to implement necessary security measures to mitigate risks.
Affected Version(s)
Application Express 5.1-19.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved