Vulnerability in Oracle Access Manager by Oracle
CVE-2020-2745

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

An improper input validation vulnerability exists in Oracle Access Manager within the Oracle Fusion Middleware suite. This issue affects certain versions, allowing an unauthenticated attacker with network access through HTTP to exploit the flaw. Successful exploitation requires user interaction from a third party, which may lead to a partial denial of service (DOS) condition. Organizations using affected versions should review their security posture and apply the necessary updates from Oracle to mitigate this risk.

Affected Version(s)

Access Manager 11.1.2.3.0

Access Manager 12.2.1.3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.