File Upload Vulnerability in Oracle E-Business Suite by Oracle
CVE-2020-2566

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

This vulnerability exists in the Oracle Applications Framework within Oracle E-Business Suite, allowing an unauthenticated attacker with network access via HTTPS to manipulate the file upload functionality. When exploited, this vulnerability can permit the attacker to gain unauthorized access to update, insert, or delete data within the Oracle Applications Framework. Successful exploitation necessitates human interaction, indicating that additional precautions may be required for user inputs and uploads. As a result, although the vulnerability is limited to the Oracle Applications Framework, it has the potential to affect the integrity of connected products.

Affected Version(s)

Applications Framework 12.1.3

Applications Framework 12.2.3-12.2.9

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.