Weakness in Oracle FLEXCUBE Investor Servicing Product of Oracle Financial Services
CVE-2020-2724

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

A security issue exists in Oracle FLEXCUBE Investor Servicing affecting multiple versions, where low-privileged attackers with network access can exploit this flaw. By leveraging HTTP protocols, these attackers could gain unauthorized read access to sensitive data within the system. This vulnerability underscores the importance of implementing robust security measures and regular updates to safeguard against potential exploit attempts.

Affected Version(s)

FLEXCUBE Investor Servicing 12.1.0-12.4.0

FLEXCUBE Investor Servicing 14.0.0-14.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.