#VU27264 Improper input validation in Oracle Retail Order Broker - CVE-2020-5398
Published: April 23, 2020 / Updated: June 3, 2020
Oracle Retail Order Broker
Oracle
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the System Administration (Spring Framework) component in Oracle Retail Order Broker. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.