First published: Wed Jan 15 2020(Updated: )
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM - LDAP user and role Synch). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Identity Manager accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Identity Management Suite | =12.2.1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2728 is a vulnerability in the Identity Manager product of Oracle Fusion Middleware, specifically in the OIM - LDAP user and role Synch component.
The severity of CVE-2020-2728 is high with a severity value of 7.5.
CVE-2020-2728 allows an unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.
The supported version of Oracle Identity Manager that is affected by CVE-2020-2728 is 12.2.1.3.0.
To fix CVE-2020-2728, it is recommended to apply the necessary patches provided by Oracle.