PT-2020-3882 · Oracle · Oracle Autovue

Owais Zaman

·

Published

2020-07-15

·

Updated

2020-07-21

·

CVE-2020-14551

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Oracle AutoVue version 21.0
Description: The issue is related to insufficient access control in the Security component of Oracle AutoVue, allowing a remote attacker to modify, add, or delete data using the HTTP protocol. This can result in unauthorized access to some of Oracle AutoVue's accessible data.
Recommendations: For Oracle AutoVue version 21.0, consider restricting access to the Security component until a patch is available. As a temporary workaround, limit the use of HTTP protocol to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04275
CVE-2020-14551

Affected Products

Oracle Autovue