Vulnerability in Oracle E-Business Suite Human Resources Application
CVE-2020-2772
4.1MEDIUM
Summary
A vulnerability exists in the Absence Recording and Maintenance component of the Oracle Human Resources product within Oracle E-Business Suite. This flaw allows a low-privileged attacker, with access to the network via HTTP, to exploit the system. Successful exploitation necessitates human interaction from an individual other than the attacker. While the vulnerability resides in Oracle Human Resources, the repercussions of such attacks can extend to other products within the suite. Attackers may gain unauthorized capabilities, resulting in the potential for updates, insertions, or deletions of sensitive data, posing significant risks to database integrity.
Affected Version(s)
Human Resources 12.2.6-12.2.9
References
CVSS V3.1
Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved