Vulnerability in Oracle Application Express of Oracle Database Server
CVE-2020-2514
4.6MEDIUM
Summary
A vulnerability in the Oracle Application Express component of Oracle Database Server allows a low privileged attacker with End User Role privileges to exploit the application, provided they have network access via HTTPS. The attack requires engagement from an unsuspecting user, which increases the risk profile. Successful exploitation can lead to unauthorized modifications including updates, inserts, and deletions of data within Oracle Application Express. Furthermore, attackers could initiate a partial denial of service, affecting the availability of the service.
Affected Version(s)
Application Express < 19.2
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved