Unauthorized Access Vulnerability in Oracle Application Express by Oracle
CVE-2020-2976

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

Oracle Application Express in the Oracle Database Server is susceptible to an improper authentication vulnerability that allows an attacker with SQL Workshop privileges to gain unauthorized access to sensitive data. This flaw can be exploited through user interaction and may lead to unauthorized updates, inserts, or deletions of accessible data. Attackers can compromise user data integrity and confidentiality, affecting the overall security of applications built on Oracle Application Express.

Affected Version(s)

Application Express 5.1-19.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.