User Interface Vulnerability in Oracle Financial Services Applications
CVE-2020-2943

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2020

Summary

A vulnerability exists in the User Interface of Oracle Financial Services Liquidity Risk Measurement and Management that allows attackers with low privileges and network access via HTTP to compromise the application. Exploiting this flaw may facilitate unauthorized creation, deletion, or modification of critical data. Additionally, there is a risk of unauthorized read access to certain data sets within the application, potentially compromising the integrity and confidentiality of sensitive information. It is essential for organizations to apply the necessary security patches to protect against such threats.

Affected Version(s)

Financial Services Liquidity Risk Measurement and Management 8.0.7

Financial Services Liquidity Risk Measurement and Management 8.0.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.