Exploitable Vulnerability in Oracle Financial Services Funds Transfer Pricing Product
CVE-2020-2941

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A flaw in the Oracle Financial Services Funds Transfer Pricing product allows low-privileged attackers with network access via HTTP to manipulate sensitive data. This vulnerability permits unauthorized creation, deletion, and modification of critical information, encompassing all accessible data within the product. It also allows for unauthorized read access, compromising the confidentiality and integrity of data. The affected versions include 8.0.6 and 8.0.7, highlighting the need for immediate patching to mitigate potential exploitation.

Affected Version(s)

Financial Services Funds Transfer Pricing 8.0.6

Financial Services Funds Transfer Pricing 8.0.7

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.