Vulnerability in Oracle Banking Corporate Lending by Oracle
CVE-2020-2715

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

A vulnerability exists in Oracle Banking Corporate Lending that can be exploited by low-privileged attackers with network access via HTTP. This flaw allows unauthorized users to perform actions such as updating, inserting, or deleting data, as well as unauthorized reading of accessible data. It affects multiple versions of the software, prompting urgent attention to ensure data confidentiality and integrity are maintained.

Affected Version(s)

Banking Corporate Lending 12.3.0-12.4.0

Banking Corporate Lending 14.0.0-14.3.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.