CVE-2020-2569
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Vulnerability in the Oracle Applications DBA component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Oracle Applications DBA executes to compromise Oracle Applications DBA. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications DBA accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Applications DBA. CVSS 3.0 Base Score 3.9 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L).
Vulnerabilidad en el componente DBA de Oracle Applications de Oracle Database Server. Las versiones compatibles que se ven afectadas son 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c y 19c. La vulnerabilidad fácilmente explotable permite que el atacante con pocos privilegios tenga privilegios de inicio de sesión local con el inicio de sesión en la infraestructura donde se ejecuta Oracle Applications DBA para comprometer Oracle Applications DBA. Los ataques con éxito requieren la interacción humana de una persona que no sea el atacante. Los ataques con éxito de esta vulnerabilidad pueden resultar en una actualización no autorizada, insertar o eliminar el acceso a algunos de los datos accesibles de Oracle Applications DBA y la capacidad no autorizada de causar una denegación parcial de servicio (parcial de DOS) de Oracle Applications DBA. Puntaje básico de CVSS 3.0 3.9 (impactos de integridad y disponibilidad). Vector CVSS: (CVSS: 3.0 / AV: L / AC: L / PR: L / UI: R / S: U / C: N / I: L / A: L).
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2019-12-10 CVE Reserved
- 2020-01-15 CVE Published
- 2023-09-14 EPSS Updated
- 2024-09-30 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.oracle.com/security-alerts/cpujan2020.html | 2022-07-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Applications Dba Search vendor "Oracle" for product "Applications Dba" | 11.2.0.4 Search vendor "Oracle" for product "Applications Dba" and version "11.2.0.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Applications Dba Search vendor "Oracle" for product "Applications Dba" | 12.1.0.2 Search vendor "Oracle" for product "Applications Dba" and version "12.1.0.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Applications Dba Search vendor "Oracle" for product "Applications Dba" | 12.2.0.1 Search vendor "Oracle" for product "Applications Dba" and version "12.2.0.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Applications Dba Search vendor "Oracle" for product "Applications Dba" | 18c Search vendor "Oracle" for product "Applications Dba" and version "18c" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Applications Dba Search vendor "Oracle" for product "Applications Dba" | 19c Search vendor "Oracle" for product "Applications Dba" and version "19c" | - |
Affected
|