Unauthenticated Access Vulnerability in Oracle E-Business Suite's Print Server
CVE-2020-2870
8.2HIGH
Summary
A vulnerability exists in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite's Print Server, allowing unauthenticated network access via HTTP. This vulnerability can be exploited by attackers to gain unauthorized access to sensitive data and manipulate it without proper authorization. Attacks require human interaction from a user other than the attacker, raising significant concerns about data confidentiality and integrity. The vulnerability affects supported versions including 12.1.1 to 12.1.3 and 12.2.3 to 12.2.9, potentially impacting other linked products.
Affected Version(s)
One-to-One Fulfillment 12.1.1-12.1.3
One-to-One Fulfillment 12.2.3-12.2.9
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved