CVE-2020-2522

4 documents4 sources
Severity
4.3MEDIUM
EPSS
1.0%
top 23.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateMay 24

Description

Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console). Supported versions that are affected are 8.6.0-8.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Knowledge …

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

ā–¶NVDoracle/knowledge8.6.0, 8.6.1+1
ā–¶CVEListV5oracle_corporation/knowledge8.6.0-8.6.1

šŸ”“Vulnerability Details

2
GHSA
GHSA-q8jw-84xc-4hch: Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console)↗2022-05-24
ā–¶
CVEList
CVE-2020-2522: Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console)↗2020-04-15
ā–¶

šŸ“‹Vendor Advisories

1
Oracle
Oracle Oracle Knowledge Risk Matrix: Information Manager Console — CVE-2020-2522↗2020-04-15
ā–¶
CVE-2020-2522 (MEDIUM CVSS 4.3) | Vulnerability in the Oracle Knowled | cvebase.io