Oracle Access Manager Authentication Engine Vulnerability in Oracle Fusion Middleware
CVE-2020-2740

4.6MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

This vulnerability pertains to the Oracle Access Manager component of Oracle Fusion Middleware, allowing an attacker with low privileges and network access via HTTP to exploit the system. Successful exploitation necessitates human interaction from a third party. Once compromised, this vulnerability can grant unauthorized access that permits updates, insertions, and deletions on data accessible by Oracle Access Manager, as well as unauthorized readings of certain data. This highlights a significant risk to the integrity and confidentiality of sensitive information managed within the Oracle Access Manager framework.

Affected Version(s)

Access Manager 11.1.2.3.0

Access Manager 12.2.1.3.0

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.