CVE Vulnerabilities

CVE-2020-14745

Published: Oct 21, 2020 | Modified: Oct 22, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General). Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c; Standalone ORDS: prior to 20.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).

Affected Software

Name Vendor Start Version End Version
Rest_data_services Oracle * 20.2.1 (excluding)
Rest_data_services Oracle 11.2.0.4 (including) 11.2.0.4 (including)
Rest_data_services Oracle 12.1.0.2 (including) 12.1.0.2 (including)
Rest_data_services Oracle 12.2.0.1 (including) 12.2.0.1 (including)
Rest_data_services Oracle 18c (including) 18c (including)
Rest_data_services Oracle 19c (including) 19c (including)

References