Vulnerability in Oracle FLEXCUBE Universal Banking by Oracle
CVE-2020-2685
5.4MEDIUM
What is CVE-2020-2685?
The Oracle FLEXCUBE Universal Banking product is susceptible to a vulnerability that enables unauthenticated network access via HTTP. This flaw could allow an attacker to manipulate the system by unauthorized actions such as updating, inserting, or deleting accessible data within FLEXCUBE. Importantly, successful exploitation requires human interaction from another individual, widening potential exposure. This vulnerability poses significant risks to data confidentiality and integrity, affecting versions between 12.0.1 and 14.3.0.
Affected Version(s)
FLEXCUBE Universal Banking 12.0.1-12.4.0
FLEXCUBE Universal Banking 14.0.0-14.3.0