PT-2020-1460 · Oracle · Oracle Human Resources

Martin Doyhenard

·

Published

2020-01-14

·

Updated

2022-04-29

·

CVE-2020-2587

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Oracle Human Resources versions 12.1.1 through 12.1.3 Oracle Human Resources versions 12.2.3 through 12.2.9
Description The issue exists due to insufficient input validation in the Hierarchy Diagrammers component of Oracle Human Resources. Exploitation of this issue may allow a remote attacker to modify, add, or delete data, gain unauthorized access to protected information, or cause a partial denial of service using the HTTPS protocol. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data, as well as unauthorized access to all accessible data in Oracle Human Resources.
Recommendations For Oracle Human Resources versions 12.1.1 through 12.1.3, update to a version that includes the fix for this issue. For Oracle Human Resources versions 12.2.3 through 12.2.9, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Hierarchy Diagrammers component until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00443
CVE-2020-2587

Affected Products

Oracle Human Resources