Unauthorized Access Vulnerability in Oracle Reports Developer by Oracle
CVE-2020-2533

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

This vulnerability in Oracle Reports Developer, a component of Oracle Fusion Middleware, exposes a significant security risk. It allows unauthenticated attackers with network access to compromise the product via HTTP. Successful exploitation necessitates human interaction from a third party, thereby heightening the risk of unauthorized updates, data modifications, or deletions. While primarily affecting Oracle Reports Developer, the ramifications could extend to other interconnected products, leading to unauthorized access to sensitive data.

Affected Version(s)

Reports Developer 12.2.1.3.0

Reports Developer 12.2.1.4.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.