PT-2020-3868 · Oracle · Oracle Commerce Service Center

Ted

·

Published

2020-07-15

·

Updated

2020-07-20

·

CVE-2020-14535

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Oracle Commerce Service Center versions 11.1, 11.2 and prior to 11.3.1
Description: The issue exists due to insufficient input validation in the Commerce Service Center module of the Oracle Commerce platform. This allows a remote attacker to gain unauthorized access to modify, add, or delete data, or access protected information via the HTTP protocol. The vulnerability can be exploited by an unauthenticated attacker with network access, potentially resulting in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all accessible data in the Oracle Commerce Service Center.
Recommendations: For versions 11.1 and 11.2, update to a version later than 11.3.1 to resolve the issue. For versions prior to 11.3.1, update to version 11.3.1 or later to fix the vulnerability. As a temporary workaround, consider restricting access to the Commerce Service Center module until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04260
CVE-2020-14535

Affected Products

Oracle Commerce Service Center