User Interface Vulnerability in Oracle Financial Services Liquidity Risk Management
CVE-2020-2891
7.1HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 15 April 2020
Summary
A security flaw has been identified in Oracle Financial Services Liquidity Risk Management, specifically within its user interface component. This weakness can be exploited by attackers with limited privileges and network access via HTTP, allowing unauthorized actions such as the creation, deletion, or modification of critical data. This vulnerability poses significant risks as it may enable unauthorized read access to a subset of sensitive data within the application, potentially jeopardizing the confidentiality and integrity of financial information.
Affected Version(s)
Financial Services Liquidity Risk Management 8.0.6
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved