Vulnerability in Oracle Workflow Product of Oracle E-Business Suite
CVE-2020-2753

5.3MEDIUM

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
15 April 2020

Summary

An unauthenticated access vulnerability exists in the Workflow Notification Mailer component of Oracle E-Business Suite. When exploited, this vulnerability allows an attacker with network access to compromise Oracle Workflow, enabling unauthorized operations such as updates, inserts, or deletions of accessible data. Supported versions 12.1.3, and 12.2.3 through 12.2.9 are notably affected, highlighting the critical need for security updates to protect sensitive workflow data.

Affected Version(s)

Workflow 12.1.3

Workflow 12.2.3-12.2.9

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.