Unauthorized Access Vulnerability in Oracle E-Business Suite Print Server
CVE-2020-2862

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

The vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite allows an unauthenticated attacker with network access via HTTP to access sensitive data. Exploiting this flaw necessitates human interaction from an individual other than the attacker, spotlighting the vulnerability's reliance on user engagement. While the direct implications are confined to the One-to-One Fulfillment, successful exploitation could have a cascading effect on other connected systems and data. This raises significant concerns regarding data confidentiality, as unauthorized read access could compromise sensitive information.

Affected Version(s)

One-to-One Fulfillment 12.1.1-12.1.3

One-to-One Fulfillment 12.2.3-12.2.9

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.