Weakness in Oracle FLEXCUBE Investor Servicing Product of Oracle Financial Services
CVE-2020-2724

4.3MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 January 2020

What is CVE-2020-2724?

A security issue exists in Oracle FLEXCUBE Investor Servicing affecting multiple versions, where low-privileged attackers with network access can exploit this flaw. By leveraging HTTP protocols, these attackers could gain unauthorized read access to sensitive data within the system. This vulnerability underscores the importance of implementing robust security measures and regular updates to safeguard against potential exploit attempts.

Affected Version(s)

FLEXCUBE Investor Servicing 12.1.0-12.4.0

FLEXCUBE Investor Servicing 14.0.0-14.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.