Unauthenticated Vulnerability in Oracle Depot Repair Product of Oracle E-Business Suite
CVE-2020-2842

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

This vulnerability in the Oracle Depot Repair component of the Oracle E-Business Suite allows an unauthenticated attacker with network access over HTTP to exploit the system. Although it primarily affects Oracle Depot Repair, the potential ramifications can extend to other products in the suite. Successful exploitation requires human interaction from a user other than the attacker and can result in unauthorized access to sensitive data, as well as malicious manipulations of accessible data within Oracle Depot Repair. The vulnerability poses a significant risk, necessitating swift remediation to protect critical organizational information.

Affected Version(s)

Depot Repair 12.1.1-12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.