Vulnerability in Oracle Application Express of Oracle Database Server
CVE-2020-2514

4.6MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability in the Oracle Application Express component of Oracle Database Server allows a low privileged attacker with End User Role privileges to exploit the application, provided they have network access via HTTPS. The attack requires engagement from an unsuspecting user, which increases the risk profile. Successful exploitation can lead to unauthorized modifications including updates, inserts, and deletions of data within Oracle Application Express. Furthermore, attackers could initiate a partial denial of service, affecting the availability of the service.

Affected Version(s)

Application Express < 19.2

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.