File Upload Vulnerability in Oracle E-Business Suite by Oracle
CVE-2020-2566
Summary
This vulnerability exists in the Oracle Applications Framework within Oracle E-Business Suite, allowing an unauthenticated attacker with network access via HTTPS to manipulate the file upload functionality. When exploited, this vulnerability can permit the attacker to gain unauthorized access to update, insert, or delete data within the Oracle Applications Framework. Successful exploitation necessitates human interaction, indicating that additional precautions may be required for user inputs and uploads. As a result, although the vulnerability is limited to the Oracle Applications Framework, it has the potential to affect the integrity of connected products.
Affected Version(s)
Applications Framework 12.1.3
Applications Framework 12.2.3-12.2.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved