Unauthenticated Access Vulnerability in Oracle E-Business Suite Customer Interaction History
CVE-2020-2873

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

The vulnerability present in the Oracle Customer Interaction History within the Oracle E-Business Suite allows an unauthenticated attacker with network access to compromise critical data. Exploitation of this flaw may require human interaction from a third party, creating a reliance on social engineering tactics. A successful attack can lead to unauthorized access to sensitive information and the ability to manipulate data through insertions, updates, or deletions. This vulnerability, therefore, poses a serious risk not only to customer data within Oracle Customer Interaction History but could potentially impact other integrated systems.

Affected Version(s)

Customer Interaction History 12.1.1-12.1.3

Customer Interaction History 12.2.3-12.2.9

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.