Unauthenticated Access Vulnerability in Oracle CRM Technical Foundation
CVE-2020-2657

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

A vulnerability exists in the Oracle CRM Technical Foundation component of Oracle E-Business Suite, specifically in the Preferences functionality. This flaw permits an unauthenticated attacker with network access via HTTPS to exploit the system. The attack requires human interaction from a user other than the attacker, making it potentially easier to manipulate. Successful exploitation of this vulnerability can lead to unauthorized modifications to Oracle CRM Technical Foundation data, including the ability to update, insert, or delete information. Although the primary impact is on the Oracle CRM Technical Foundation, the ramifications may extend to other interconnected products within the E-Business Suite, heightening the overall risk profile.

Affected Version(s)

CRM Technical Foundation 12.1.3

CRM Technical Foundation 12.2.3-12.2.9

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.