First published: Wed Apr 15 2020(Updated: )
Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction History. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Customer Interaction History | >=12.1.1<=12.1.3 | |
Oracle Customer Interaction History | >=12.2.3<=12.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2887 has a high severity rating due to the potential for unauthenticated attackers to exploit the vulnerability remotely.
To fix CVE-2020-2887, apply the latest security patches released by Oracle for the affected versions of Oracle Customer Interaction History.
CVE-2020-2887 affects Oracle Customer Interaction History versions from 12.1.1 to 12.1.3 and 12.2.3 to 12.2.9.
Yes, CVE-2020-2887 is considered easily exploitable as it allows unauthenticated network access via HTTP.
CVE-2020-2887 affects the Outcome-Result component of the Oracle Customer Interaction History product.