User Interface Vulnerability in Oracle Financial Services Liquidity Risk Management
CVE-2020-2891

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A security flaw has been identified in Oracle Financial Services Liquidity Risk Management, specifically within its user interface component. This weakness can be exploited by attackers with limited privileges and network access via HTTP, allowing unauthorized actions such as the creation, deletion, or modification of critical data. This vulnerability poses significant risks as it may enable unauthorized read access to a subset of sensitive data within the application, potentially jeopardizing the confidentiality and integrity of financial information.

Affected Version(s)

Financial Services Liquidity Risk Management 8.0.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.