CVE-2020-2714: Medium severity ORACLE Banking Payments vulnerability
Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 14.1.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Banking Payments accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Oracle Financial Services Applications vulnerability?
The vulnerability ID for this Oracle Financial Services Applications vulnerability is CVE-2020-2714.
What is the affected version range of Oracle Banking Payments?
The affected version range of Oracle Banking Payments is 14.1.0 to 14.3.0.
How can this vulnerability be exploited?
This vulnerability can be exploited by a low privileged attacker with network access via HTTP to compromise Oracle Banking Payments.
What is the severity of CVE-2020-2714?
The severity of CVE-2020-2714 is medium (4.3).
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at: https://www.oracle.com/security-alerts/cpujan2020.html