Unauthenticated Access Vulnerability in Oracle E-Business Suite's One-to-One Fulfillment
CVE-2020-2597

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

A vulnerability exists in the Oracle One-to-One Fulfillment component of the Oracle E-Business Suite that could allow unauthenticated attackers to compromise the system. When exploited, this vulnerability could enable an attacker to interact with the application in ways that result in unauthorized modifications to accessible data. Although successful exploitation requires human interaction from a user other than the attacker, the potential impact on Oracle One-to-One Fulfillment could extend to connected products and services, raising significant security concerns.

Affected Version(s)

One-to-One Fulfillment 12.1.1-12.1.3

One-to-One Fulfillment 12.2.3-12.2.9

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.