Remote Access Vulnerability in Oracle E-Business Suite's CRM Technical Foundation
CVE-2020-2881

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

This vulnerability within the Oracle CRM Technical Foundation of the Oracle E-Business Suite allows an unauthenticated attacker to gain access to sensitive data. Exploitation of this flaw can occur through HTTP, requiring human interaction from a user, which may compromise not only the CRM component but also affect other associated products. Successful exploitation can lead to unauthorized access and manipulation of critical data, including the ability to update, insert, or delete records within the CRM system.

Affected Version(s)

CRM Technical Foundation 12.1.1-12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.