Oracle FLEXCUBE Universal Banking Vulnerability in Infrastructure Component
CVE-2020-2699
7.1HIGH
Summary
An access control vulnerability in Oracle FLEXCUBE Universal Banking, specifically within the Infrastructure component, allows low-privileged attackers with network access via HTTP to potentially compromise sensitive data. Successful exploitation could lead to unauthorized access to critical information stored within the database, as well as the ability to modify, insert, or delete data that the attacker can access. This vulnerability underscores the need for robust security measures and timely application of patches.
Affected Version(s)
FLEXCUBE Universal Banking 12.0.1-12.4.0
FLEXCUBE Universal Banking 14.0.0-14.3.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved