Remote Code Execution Flaw in Oracle E-Business Suite's Print Server
CVE-2020-2825

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability exists in Oracle E-Business Suite’s Print Server, impacting its One-to-One Fulfillment component. This flaw is easily exploitable by an unauthenticated attacker with HTTP network access, allowing the attacker to compromise the affected systems. Although human interaction is needed from someone other than the attacker for successful exploitation, the implications can be severe. Attackers may gain unauthorized access to sensitive data, potentially leading to unauthorized updates, inserts, or deletions of data within Oracle One-to-One Fulfillment. This vulnerability could result in a significant breach of confidentiality and integrity, affecting critical information within the Oracle ecosystem.

Affected Version(s)

One-to-One Fulfillment 12.1.1-12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.