First published: Wed Oct 21 2020(Updated: )
Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Pre Login). Supported versions that are affected are 12.0.1, 12.0.2 and 12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Direct Banking. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Direct Banking accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle FLEXCUBE Direct Banking | =12.0.1 | |
Oracle FLEXCUBE Direct Banking | =12.0.2 | |
Oracle FLEXCUBE Direct Banking | =12.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14890 has been classified as a critical vulnerability due to its potential for exploitation by unauthenticated attackers.
To fix CVE-2020-14890, you should apply the latest security patches provided by Oracle for versions 12.0.1, 12.0.2, and 12.0.3 of FLEXCUBE Direct Banking.
Organizations using Oracle FLEXCUBE Direct Banking versions 12.0.1, 12.0.2, and 12.0.3 are affected by CVE-2020-14890.
Yes, CVE-2020-14890 can be remotely exploited by an unauthenticated attacker with network access via HTTP.
CVE-2020-14890 affects the Pre Login component of the Oracle FLEXCUBE Direct Banking product.