PT-2020-3882 · Oracle · Oracle Autovue
Owais Zaman
·
Published
2020-07-15
·
Updated
2020-07-21
·
CVE-2020-14551
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Oracle AutoVue version 21.0
Description:
The issue is related to insufficient access control in the Security component of Oracle AutoVue, allowing a remote attacker to modify, add, or delete data using the HTTP protocol. This can result in unauthorized access to some of Oracle AutoVue's accessible data.
Recommendations:
For Oracle AutoVue version 21.0, consider restricting access to the Security component until a patch is available. As a temporary workaround, limit the use of HTTP protocol to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Autovue