Unauthorized Access Vulnerability in Oracle Application Express by Oracle
CVE-2020-2976
5.4MEDIUM
Summary
Oracle Application Express in the Oracle Database Server is susceptible to an improper authentication vulnerability that allows an attacker with SQL Workshop privileges to gain unauthorized access to sensitive data. This flaw can be exploited through user interaction and may lead to unauthorized updates, inserts, or deletions of accessible data. Attackers can compromise user data integrity and confidentiality, affecting the overall security of applications built on Oracle Application Express.
Affected Version(s)
Application Express 5.1-19.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved