Denial of Service Vulnerability in Oracle Knowledge by Oracle
CVE-2020-2524

5.9MEDIUM

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability exists in the Oracle Knowledge component, specifically within the InQuira Search. This weakness permits an unauthenticated attacker with HTTP network access to potentially disrupt service continuity. Exploitation may lead to situations where the system can hang or experience frequent crashes, thereby resulting in a Denial of Service condition. Supported versions that are susceptible include 8.6.0 through 8.6.3. This vulnerability underscores the importance of securing Oracle Knowledge environments against unauthorized interference.

Affected Version(s)

Knowledge 8.6.0-8.6.3

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.