Oracle · Oracle Financial Services Analytical Applications Infrastructure · CVE-2020-14602
**Name of the Vulnerable Software and Affected Versions**
Oracle Financial Services Analytical Applications Infrastructure versions 8.0.6 through 8.1.0
**Description**
The issue is related to insufficient input validation in the Infrastructure component of Oracle Financial Services Analytical Applications Infrastructure. This can allow a remote attacker to gain unauthorized access to protected information or modify, add, or delete data. The vulnerability can be exploited by a low-privileged attacker with network access via HTTP, potentially resulting in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of data.
**Recommendations**
For versions 8.0.6 through 8.1.0, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the Infrastructure component to minimize the risk of unauthorized data access or modification.