Unauthenticated Access Vulnerability in Oracle E-Business Suite iSupport Component
CVE-2020-2878
8.2HIGH
Summary
A vulnerability exists in the iSupport component of Oracle E-Business Suite, allowing unauthenticated attackers with HTTP access to exploit the system. Successful exploitation could grant unauthorized access to sensitive data and the ability to modify, delete, or insert data within iSupport. While the attack necessitates human interaction, it poses significant risks to the integrity and confidentiality of affected data. This vulnerability highlights the importance of protecting Oracle iSupport instances to mitigate potential security breaches.
Affected Version(s)
iSupport 12.1.1-12.1.3
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved