#VU52502 Improper input validation in Oracle Communications Converged Application Server - CVE-2020-27218
Published: April 23, 2021
Oracle Communications Converged Application Server
Oracle
Description
The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.
The vulnerability exists due to improper input validation within the SC Admin server (Eclipse Jetty) component in Oracle Communications Converged Application Server - Service Controller. A remote non-authenticated attacker can exploit this vulnerability to manipulate or delete data.