Vulnerability in Oracle E-Business Intelligence exposes sensitive data
CVE-2020-2840

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability in Oracle E-Business Intelligence allows an unauthenticated attacker to exploit the system through network access. This vulnerability requires human interaction from a person other than the attacker for successful exploitation. An attacker can compromise Oracle E-Business Intelligence, potentially resulting in unauthorized access to sensitive information and granting the ability to perform unauthorized updates, insertions, or deletions on critical data. The implications of this vulnerability extend beyond Oracle E-Business Intelligence, potentially affecting other connected products.

Affected Version(s)

E-Business Intelligence 12.1.1-12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.