Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Vaibhav Shukla

#41264of 53,633
6.5Total CVSS
Vulnerabilities · 1
PT-2020-2382
6.5
2020-04-15
Oracle · Oracle Flexcube Core Banking · CVE-2020-2955
**Name of the Vulnerable Software and Affected Versions** Oracle FLEXCUBE Core Banking version 4.0 **Description** The issue affects the Transaction Processing component of Oracle FLEXCUBE Core Banking, allowing a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized update, insert, or delete access to some data, as well as unauthorized read access to a subset of data and the ability to cause a partial denial of service. The vulnerability is easily exploitable and can be used to create, delete, or modify access rights to protected information. **Recommendations** For Oracle FLEXCUBE Core Banking version 4.0, consider restricting access to the Transaction Processing component until a patch is available. As a temporary workaround, limit the use of HTTP requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.