Vulnerability in Oracle E-Business Suite Universal Work Queue
CVE-2020-2818

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

An exploitable vulnerability exists in the Oracle Universal Work Queue component of Oracle E-Business Suite. This issue enables unauthenticated attackers to gain network access via HTTP, compromising the Universal Work Queue. Although successful exploitation requires human interaction from a third-party user, the attack may have widespread implications, potentially affecting multiple products within the suite. Attackers could gain unauthorized access to sensitive information and perform unpredictable modifications to accessible data. This vulnerability underscores the importance of securing configurations and applying security updates promptly to safeguard sensitive data.

Affected Version(s)

Universal Work Queue 12.1.1-12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.