CVE-2020-2939
Last modified
CVE-2020-2939 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Vulnerability in the Oracle Financial Services Asset Liability Management product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 and 8.0.7. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
Vulnerability in the Oracle Financial Services Asset Liability Management product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 and 8.0.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Asset Liability Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Asset Liability Management accessible data as well as unauthorized read access to a subset of Oracle Financial Services Asset Liability Management accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Financial Services Asset Liability Management | 8.0.6 |
| Oracle | Financial Services Asset Liability Management | 8.0.7 |
References
- https://www.oracle.com/security-alerts/cpuapr2020.htmlPatch, Vendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-2939?
How severe is CVE-2020-2939?
How do I fix CVE-2020-2939?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-29381An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.5…9.8
- CVE-2020-29382An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.5…7.8
- CVE-2020-29383An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600…7.8
- CVE-2020-29384An issue was discovered in PNGOUT 2020-01-15. When compressi…5.5
- CVE-2020-29385GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a deni…5.5
- CVE-2020-29389The official Crux Linux Docker images 3.0 through 3.4 contai…9.8
- CVE-2020-29390Zeroshell 3.9.3 contains a command injection vulnerability i…9.8
- CVE-2020-29392The Estil Hill Lock Password Manager Safe app 2.3 for iOS ha…4.6
- CVE-2020-29394A buffer overflow in the dlt_filter_load function in dlt_com…7.8
- CVE-2020-29395The EventON plugin through 3.0.5 for WordPress allows addons…6.1
- CVE-2020-29396A sandboxing issue in Odoo Community 11.0 through 13.0 and O…8.8
- CVE-2020-29397Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2020-2939?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
