CVE-2020-2753: Medium severity oracle workflow vulnerability
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2753?
The severity of CVE-2020-2753 is medium (5.3).
What is the affected software for CVE-2020-2753?
The affected software for CVE-2020-2753 is Oracle Workflow versions 12.1.3 and 12.2.3-12.2.9.
How can an attacker exploit CVE-2020-2753?
An unauthenticated attacker with network access via HTTP can easily exploit CVE-2020-2753 to compromise Oracle Workflow.
What is the reference for CVE-2020-2753?
The reference for CVE-2020-2753 is [here](https://www.oracle.com/security-alerts/cpuapr2020.html).
How do I fix CVE-2020-2753?
To fix CVE-2020-2753, apply the necessary patches provided by Oracle.