Oracle FLEXCUBE Universal Banking Vulnerability in Infrastructure Component
CVE-2020-2700
4.3MEDIUM
Summary
An improper access control vulnerability exists within the Oracle FLEXCUBE Universal Banking product, specifically in the Infrastructure component. This issue allows low-privileged attackers with network access via HTTP to exploit the system, potentially leading to unauthorized read access to some accessible data. Users of supported versions 12.0.1 through 12.4.0 and 14.0.0 through 14.3.0 are particularly at risk, as successful exploitation can compromise sensitive information. It is essential to implement necessary security measures to mitigate potential threats originating from this vulnerability.
Affected Version(s)
FLEXCUBE Universal Banking 12.0.1-12.4.0
FLEXCUBE Universal Banking 14.0.0-14.3.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved