Unauthenticated Access Vulnerability in Oracle CRM Technical Foundation by Oracle
CVE-2020-2889
5.3MEDIUM
Summary
A vulnerability exists in the Oracle CRM Technical Foundation component of Oracle E-Business Suite which allows an unauthenticated attacker with network access via HTTP to compromise the system. This vulnerability can lead to unauthorized read access to a subset of accessible data within the Oracle CRM Technical Foundation. Affected users should apply relevant security updates promptly to mitigate the risks associated with this vulnerability.
Affected Version(s)
CRM Technical Foundation 12.1.3
CRM Technical Foundation 12.2.3-12.2.9
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved