Improper input validation in Oracle Commerce Merchandising - CVE-2020-27193

 

Improper input validation in Oracle Commerce Merchandising - CVE-2020-27193

Published: April 23, 2021


Vulnerability identifier: #VU52500
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27193
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The vulnerability exists due to improper input validation within the Experience Manager, Business Control Center (CKEditor) component in Oracle Commerce Merchandising. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.


Affected software

Oracle Commerce Merchandising
Oracle Banking Platform
Oracle Financial Services Analytical Applications Infrastructure
IBM Engineering Requirements Management DOORS Next
Oracle Banking Party Management
PeopleSoft Enterprise PeopleTools
Oracle Application Express

How to mitigate CVE-2020-27193

Install updates from vendor's website.

IBM Engineering Requirements Management DOORS Next - update to 9.7.2.8
Oracle Application Express - update to 21.1.0.00.01

External References

Related Security Bulletins