Unauthenticated Network Vulnerability in Oracle One-to-One Fulfillment
CVE-2020-2824

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability exists in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite, specifically in the Print Server. This flaw allows unauthenticated attackers with network access via HTTP to exploit the system, requiring human interaction for successful attacks. The exploitation of this vulnerability can lead to unauthorized access to sensitive data, potentially compromising the integrity of data stored within Oracle One-to-One Fulfillment. Attackers could gain extensive access, enabling them to update, insert, or delete critical information. The presence of this flaw could also impact other products within the suite.

Affected Version(s)

One-to-One Fulfillment 12.1.1-12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.