Unauthenticated Vulnerability in Oracle Depot Repair Product of Oracle E-Business Suite
CVE-2020-2842
8.2HIGH
Summary
This vulnerability in the Oracle Depot Repair component of the Oracle E-Business Suite allows an unauthenticated attacker with network access over HTTP to exploit the system. Although it primarily affects Oracle Depot Repair, the potential ramifications can extend to other products in the suite. Successful exploitation requires human interaction from a user other than the attacker and can result in unauthorized access to sensitive data, as well as malicious manipulations of accessible data within Oracle Depot Repair. The vulnerability poses a significant risk, necessitating swift remediation to protect critical organizational information.
Affected Version(s)
Depot Repair 12.1.1-12.1.3
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved