Security Vulnerability in Oracle Email Center of Oracle E-Business Suite
CVE-2020-2796

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability in Oracle Email Center within the Oracle E-Business Suite enables unauthenticated attackers with network access to compromise the service. While it specifically exists in the Email Center, successful exploitation may lead to unauthorized access and manipulation of sensitive data across affected products. This vulnerability requires human interaction to execute successfully, making it particularly concerning for organizations that rely on the affected versions. Attackers can achieve unauthorized access to confidential information, and they may also manipulate data by performing operations such as updating, inserting, or deleting entries within the Oracle Email Center.

Affected Version(s)

Email Center 12.1.1-12.1.3

Email Center 12.2.3-12.2.9

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.