HTTP Exploitation Vulnerability in Oracle Retail Customer Management Software
CVE-2020-2567
4.8MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 15 January 2020
Summary
The Oracle Retail Customer Management and Segmentation Foundation contains an easily exploitable security vulnerability that could allow a high-privileged attacker to compromise the system via network access through HTTP. While the attack requires human interaction from a user other than the attacker, successful exploitation may lead to unauthorized modifications, including update, insert, or deletion of accessible data. Furthermore, this vulnerability could allow unauthorized read access to certain data within the Oracle Retail Customer Management and Segmentation Foundation, potentially impacting additional connected products.
Affected Version(s)
Retail Customer Management and Segmentation Foundation 18.0
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved