Vulnerability in Oracle Application Express Affects Oracle Database Server
CVE-2020-2977

4.6MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 July 2020

Summary

This vulnerability in the Oracle Application Express component of Oracle Database Server allows a low-privileged attacker with valid network access via HTTP to exploit the system. Successful exploitation requires human interaction from a third party, enabling unauthorized update, insert, or deletion of data. Additionally, it permits unauthorized read access to a limited subset of data accessible within Oracle Application Express. This flaw highlights critical risks in data security and emphasizes the importance of ensuring all users adhere to stringent access controls.

Affected Version(s)

Application Express 5.1-19.2

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.