Unauthorized Access Vulnerability in Oracle Reports Developer by Oracle
CVE-2020-2533
6.1MEDIUM
Summary
This vulnerability in Oracle Reports Developer, a component of Oracle Fusion Middleware, exposes a significant security risk. It allows unauthenticated attackers with network access to compromise the product via HTTP. Successful exploitation necessitates human interaction from a third party, thereby heightening the risk of unauthorized updates, data modifications, or deletions. While primarily affecting Oracle Reports Developer, the ramifications could extend to other interconnected products, leading to unauthorized access to sensitive data.
Affected Version(s)
Reports Developer 12.2.1.3.0
Reports Developer 12.2.1.4.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved