SQL Injection Vulnerability in Oracle Application Express of Oracle Database Server
CVE-2020-2971

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

A vulnerability exists in the Oracle Application Express component of Oracle Database Server, allowing low-privileged attackers with SQL Workshop privileges to exploit it. This exploit requires human interaction from a third party, potentially compromising accessible data. Attackers may gain unauthorized access to update, insert, or delete data, as well as read a limited subset of this data, posing significant risks to data integrity and confidentiality.

Affected Version(s)

Application Express 5.1-19.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.