CVE-2020-14855 is a critical vulnerability affecting Oracle Universal Work Queue in Oracle E-Business Suite version 12.1.3. This easily exploitable flaw allows an unauthenticated attacker with network access via HTTP to fully compromise the affected system, leading to complete loss of confidentiality, integrity, and availability. With a CVSS v3.1 score of 9.8, the risk is severe, enabling a full takeover of the Universal Work Queue. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the potential impact remains extremely high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:universal_work_queue:12.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.