Unauthenticated Vulnerability in Oracle One-to-One Fulfillment Product by Oracle
CVE-2020-2827

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

The vulnerability in Oracle One-to-One Fulfillment allows attackers to gain unauthorized access to sensitive data through network access via HTTP. An attacker can exploit this flaw without authentication, although the attack requires interaction from another user. This makes it particularly dangerous, as successful exploitation can lead to unauthorized updates, insertions, or deletions of data, impacting not only the Oracle One-to-One Fulfillment product but potentially other integrated components of the Oracle E-Business Suite.

Affected Version(s)

One-to-One Fulfillment 12.1.1-12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.