Improper input validation in Oracle Financial Services Regulatory Reporting with AgileREPORTER - CVE-2020-7712
Published: July 22, 2021
Vulnerability identifier: #VU55238
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-7712
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Reports (Apache ZooKeeper) component in Oracle Financial Services Regulatory Reporting with AgileREPORTER. A remote privileged user can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle Financial Services Regulatory Reporting with AgileREPORTER
Oracle Financial Services Crime and Compliance Management Studio
Oracle Commerce Guided Search
Oracle Siebel CRM
Oracle TimesTen In-Memory Database
Oracle Financial Services Crime and Compliance Management Studio
Oracle Commerce Guided Search
Oracle Siebel CRM
Oracle TimesTen In-Memory Database
How to mitigate CVE-2020-7712
Install updates from vendor's website.
Oracle Siebel CRM - update to 22.6
Oracle TimesTen In-Memory Database - update to 21.1.1.1.0
Oracle TimesTen In-Memory Database - update to 21.1.1.1.0
External References
Related Security Bulletins
- Improper input validation in Oracle Financial Services Regulatory Reporting with AgileREPORTER
- Multiple vulnerabilities in Oracle TimesTen In-Memory Database
- Multiple vulnerabilities in Oracle Commerce Guided Search
- Multiple vulnerabilities in Oracle Financial Services Crime and Compliance Management Studio
- Multiple vulnerabilities in Oracle Siebel CRM