Unauthorized Data Manipulation Vulnerability in Oracle Customer Interaction History
CVE-2020-2887
5.3MEDIUM
Summary
An unauthenticated attacker can exploit a vulnerability in the Oracle Customer Interaction History within the Oracle E-Business Suite. This weakness allows attackers with network access to the system to perform unauthorized actions such as updating, inserting, or deleting data within the Customer Interaction History module. Affected versions include 12.1.1 through 12.1.3 and 12.2.3 through 12.2.9, highlighting the critical nature of keeping software up to date to prevent potential data breaches.
Affected Version(s)
Customer Interaction History 12.1.1-12.1.3
Customer Interaction History 12.2.3-12.2.9
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved