#VU49857 Improper input validation in Oracle Retail Order Broker Cloud Service - CVE-2020-13954
Published: January 20, 2021
Oracle Retail Order Broker Cloud Service
Oracle
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Supplier Direct Fulfillment (Apache CXF) component in Oracle Retail Order Broker Cloud Service. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.