PT-2020-2498 · Oracle · Oracle Outside In Technology

Kasper Leigh Haabb

·

Published

2020-04-14

·

Updated

2022-10-14

·

CVE-2020-2786

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Outside In Technology version 8.5.4
Description The issue is related to insufficient access controls in the Outside In Filters component of Oracle Outside In Technology, a software development kit (SDK). This can be exploited by a remote attacker to gain unauthorized access to protected information or cause a partial denial of service using the HTTP protocol. Successful attacks can result in unauthorized update, insert, or delete access to some data, as well as unauthorized read access to a subset of data.
Recommendations For version 8.5.4, consider restricting access to the Outside In Filters component to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the use of the HTTP protocol to reduce the potential for remote attacks.

Fix

Weakness Enumeration

Related Identifiers

BDU:2020-02509
CVE-2020-2786

Affected Products

Oracle Outside In Technology