Exploitable Vulnerability in Oracle Financial Services Funds Transfer Pricing Product
CVE-2020-2941
7.1HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 15 April 2020
Summary
A flaw in the Oracle Financial Services Funds Transfer Pricing product allows low-privileged attackers with network access via HTTP to manipulate sensitive data. This vulnerability permits unauthorized creation, deletion, and modification of critical information, encompassing all accessible data within the product. It also allows for unauthorized read access, compromising the confidentiality and integrity of data. The affected versions include 8.0.6 and 8.0.7, highlighting the need for immediate patching to mitigate potential exploitation.
Affected Version(s)
Financial Services Funds Transfer Pricing 8.0.6
Financial Services Funds Transfer Pricing 8.0.7
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved