CVE-2020-2592

Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Security). The supported version that is affected is 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle AutoVue accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:autovue:21.0.2:*:*:*:*:*:*:*

History

21 Nov 2024, 05:25

Type Values Removed Values Added
References () https://www.oracle.com/security-alerts/cpujan2020.html - Patch, Vendor Advisory () https://www.oracle.com/security-alerts/cpujan2020.html - Patch, Vendor Advisory

25 Oct 2022, 17:56

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:autovue:12.0.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:autovue:21.0.2:*:*:*:*:*:*:*

Information

Published : 2020-01-15 17:15

Updated : 2024-11-21 05:25


NVD link : CVE-2020-2592

Mitre link : CVE-2020-2592

CVE.ORG link : CVE-2020-2592


JSON object : View

Products Affected

oracle

  • autovue