First published: Wed Jul 15 2020(Updated: )
Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications Applications (component: File Upload). Supported versions that are affected are 8.1.0, 8.2.0 and 8.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Session Border Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Session Border Controller as well as unauthorized update, insert or delete access to some of Oracle Enterprise Session Border Controller accessible data and unauthorized read access to a subset of Oracle Enterprise Session Border Controller accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Enterprise Session Border Controller | =8.1.0 | |
Oracle Enterprise Session Border Controller | =8.2.0 | |
Oracle Enterprise Session Border Controller | =8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Oracle Enterprise Session Border Controller vulnerability is CVE-2020-14630.
The affected software for this vulnerability is Oracle Enterprise Session Border Controller version 8.1.0, 8.2.0, and 8.3.0.
CVE-2020-14630 has a severity level of 7.5 (high).
This vulnerability can be easily exploited by a high privileged attacker with network access via HTTP to upload malicious files.
Yes, Oracle has released a fix for this vulnerability. Please refer to the official Oracle Security Advisory for more information.