Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-2597

Опубликовано: 15 янв. 2020
Источник: nvd
CVSS3: 4.7
CVSS3: 4.7
CVSS2: 4.3
EPSS Низкий

Описание

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Call Phone Number Page). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:oracle:one-to-one_fulfillment:*:*:*:*:*:*:*:*
Версия от 12.1.1 (включая) до 12.1.3 (включая)
cpe:2.3:a:oracle:one-to-one_fulfillment:*:*:*:*:*:*:*:*
Версия от 12.2.3 (включая) до 12.2.9 (включая)

EPSS

Процентиль: 76%
0.00978
Низкий

4.7 Medium

CVSS3

4.7 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.7
github
больше 3 лет назад

Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Call Phone Number Page). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).

CVSS3: 4.7
fstec
около 6 лет назад

Уязвимость подкомпонента Call Phone Number Page компонента Oracle One-to-One Fulfillment системы автоматизации деятельности предприятия Oracle E-Business Suite, позволяющая нарушителю получить доступ на изменение, добавление или удаление данных

EPSS

Процентиль: 76%
0.00978
Низкий

4.7 Medium

CVSS3

4.7 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

NVD-CWE-noinfo