CVE-2020-2592: Medium severity Oracle AutoVue vulnerability
Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Security). The supported version that is affected is 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle AutoVue accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
oracle/autovue/securityto a version that resolves this vulnerability.Fixed in 21.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2592?
The severity of CVE-2020-2592 is medium with a severity score of 5.3.
What is the affected version of Oracle AutoVue in CVE-2020-2592?
The affected version of Oracle AutoVue in CVE-2020-2592 is 21.0.2.
How can an attacker exploit CVE-2020-2592?
An unauthenticated attacker with network access via HTTP can exploit CVE-2020-2592.
What is the recommended action to fix CVE-2020-2592?
To fix CVE-2020-2592, apply the necessary patches provided by Oracle.
Where can I find more information about CVE-2020-2592?
More information about CVE-2020-2592 can be found on the Oracle Security Alerts website: [reference link](https://www.oracle.com/security-alerts/cpujan2020.html).