Authentication Bypass in Oracle Email Center of Oracle E-Business Suite
CVE-2020-2669

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

An authentication bypass vulnerability exists in Oracle Email Center, a component of Oracle E-Business Suite. This flaw allows unauthenticated attackers with network access via HTTPS to compromise the application. Exploitation requires human interaction from a separate individual, which potentially broadens the attack surface. Although primarily affecting Oracle Email Center, the implications could extend to other integrated products, permitting unauthorized access to sensitive data. Attackers could execute unauthorized operations such as updating, inserting, or deleting critical data, thereby significantly compromising the integrity and confidentiality of stored information.

Affected Version(s)

Email Center 12.1.1-12.1.3

Email Center 12.2.3-12.2.9

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.