SQL Injection Vulnerability in Oracle Application Express of Oracle Database Server
CVE-2020-2971
5.4MEDIUM
Summary
A vulnerability exists in the Oracle Application Express component of Oracle Database Server, allowing low-privileged attackers with SQL Workshop privileges to exploit it. This exploit requires human interaction from a third party, potentially compromising accessible data. Attackers may gain unauthorized access to update, insert, or delete data, as well as read a limited subset of this data, posing significant risks to data integrity and confidentiality.
Affected Version(s)
Application Express 5.1-19.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved