Unauthenticated Access Vulnerability in Oracle CRM Technical Foundation
CVE-2020-2657
Summary
A vulnerability exists in the Oracle CRM Technical Foundation component of Oracle E-Business Suite, specifically in the Preferences functionality. This flaw permits an unauthenticated attacker with network access via HTTPS to exploit the system. The attack requires human interaction from a user other than the attacker, making it potentially easier to manipulate. Successful exploitation of this vulnerability can lead to unauthorized modifications to Oracle CRM Technical Foundation data, including the ability to update, insert, or delete information. Although the primary impact is on the Oracle CRM Technical Foundation, the ramifications may extend to other interconnected products within the E-Business Suite, heightening the overall risk profile.
Affected Version(s)
CRM Technical Foundation 12.1.3
CRM Technical Foundation 12.2.3-12.2.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved