PT-2020-2605 · Oracle · Oracle Knowledge

Published

2020-04-15

·

Updated

2020-04-16

·

CVE-2020-2795

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Knowledge versions 8.6.0 through 8.6.2
Description The issue is related to insufficient input validation in the Information Manager Console component of Oracle Knowledge. It allows a high-privileged attacker with logon access to the infrastructure where Oracle Knowledge is executed to compromise Oracle Knowledge. Successful attacks require human interaction from a person other than the attacker and can result in the takeover of Oracle Knowledge. The exploitation can be done remotely via the HTTP protocol, impacting the confidentiality, integrity, and availability of the protected information.
Recommendations For Oracle Knowledge versions 8.6.0 through 8.6.2, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02639
CVE-2020-2795

Affected Products

Oracle Knowledge