Vulnerability in Oracle Banking Payments Product by Oracle
CVE-2020-2712

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

The vulnerability in Oracle Banking Payments allows an unauthenticated attacker with network access via HTTP to exploit the system. Although human interaction is required from another party for a successful attack, the potential consequences are severe. Attackers could gain unauthorized access to modify or delete sensitive data, as well as read certain accessible data within the application. This vulnerability highlights the importance of thorough security practices and robust access controls to protect against unwanted exploitation.

Affected Version(s)

Banking Payments 14.1.0-14.3.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.