PT-2020-2495 · Oracle · Oracle Outside In Technology

Kasper Leigh Haabb

·

Published

2020-04-14

·

Updated

2022-10-14

·

CVE-2020-2783

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle Outside In Technology versions 8.5.4
Description The issue is related to insufficient access controls in the Outside In Filters component of Oracle Outside In Technology, a suite of software development kits (SDKs). This can be exploited by an unauthenticated attacker with network access via the HTTP protocol to compromise Oracle Outside In Technology, potentially leading to unauthorized update, insert, or delete access to some accessible data.
Recommendations For version 8.5.4, update to a version that includes the fix for this issue to prevent unauthorized access and potential data manipulation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2020-02506
CVE-2020-2783

Affected Products

Oracle Outside In Technology