Vulnerability in Oracle FLEXCUBE Core Banking Product by Oracle Financial Services Applications
CVE-2020-2955
6.3MEDIUM
What is CVE-2020-2955?
An easily exploitable vulnerability exists in the Oracle FLEXCUBE Core Banking product, allowing attackers with low-level privileges to gain unauthorized access. These attackers can manipulate data through unauthorized updates, inserts, and deletes, as well as access confidential information. Additionally, they may potentially induce a partial denial of service, affecting the availability of the system. The attack vector is via HTTP, making it particularly concerning for network-based threats.
Affected Version(s)
FLEXCUBE Core Banking 4.0