PT-2020-3868 · Oracle · Oracle Commerce Service Center
Ted
·
Published
2020-07-15
·
Updated
2020-07-20
·
CVE-2020-14535
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Oracle Commerce Service Center versions 11.1, 11.2 and prior to 11.3.1
Description:
The issue exists due to insufficient input validation in the Commerce Service Center module of the Oracle Commerce platform. This allows a remote attacker to gain unauthorized access to modify, add, or delete data, or access protected information via the HTTP protocol. The vulnerability can be exploited by an unauthenticated attacker with network access, potentially resulting in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all accessible data in the Oracle Commerce Service Center.
Recommendations:
For versions 11.1 and 11.2, update to a version later than 11.3.1 to resolve the issue.
For versions prior to 11.3.1, update to version 11.3.1 or later to fix the vulnerability.
As a temporary workaround, consider restricting access to the Commerce Service Center module until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Commerce Service Center