CVE-2020-2700: Medium severity Oracle FLEXCUBE Universal Banking vulnerability
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-2700.
What product is affected by this vulnerability?
The Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications is affected.
What versions of the Oracle FLEXCUBE Universal Banking product are affected?
Versions 12.0.1 to 12.4.0 and 14.0.0 to 14.3.0 are affected.
How severe is this vulnerability?
This vulnerability has a severity rating of 4.3, which is considered medium.
How can this vulnerability be exploited?
This vulnerability can be exploited by a low privileged attacker with network access via HTTP.