Improper input validation in Oracle Retail Order Broker Cloud Service - CVE-2020-13954

 

Improper input validation in Oracle Retail Order Broker Cloud Service - CVE-2020-13954

Published: January 20, 2021


Vulnerability identifier: #VU49857
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13954
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The vulnerability exists due to improper input validation within the Supplier Direct Fulfillment (Apache CXF) component in Oracle Retail Order Broker Cloud Service. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.


Affected software

Oracle Retail Order Broker Cloud Service
IBM Intelligent Operations Center
InfoSphere Master Data Management
IBM Qradar SIEM
Oracle Communications Instant Messaging Server
Voice Gateway
IBM Security Guardium
Oracle WebCenter Sites

How to mitigate CVE-2020-13954

Install updates from vendor's website.

IBM Intelligent Operations Center - update to 5.2.4
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
InfoSphere Master Data Management - update to 11.6.0.12

External References

Related Security Bulletins