Exploitable Vulnerability in Oracle FLEXCUBE Universal Banking by Oracle
CVE-2020-2683

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

An exploitable vulnerability exists in the Oracle FLEXCUBE Universal Banking product, affecting versions 12.0.1 to 12.4.0 and 14.0.0 to 14.3.0. This vulnerability allows a low privileged attacker with network access via HTTPS to manipulate data. Successful exploitation could lead to unauthorized updates, inserts, or deletions of accessible data and grant unauthorized read access to certain data within Oracle FLEXCUBE Universal Banking. Organizations using the affected versions are advised to apply necessary patches and ensure their systems are secured.

Affected Version(s)

FLEXCUBE Universal Banking 12.0.1-12.4.0

FLEXCUBE Universal Banking 14.0.0-14.3.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.