CVE-2020-2586 is a critical vulnerability in the Hierarchy Diagrammers component of Oracle Human Resources within Oracle E-Business Suite versions 12.1.1-12.1.3 and 12.2.3-12.2.9. This easily exploitable flaw allows a low-privileged attacker with network access via HTTPS to compromise Oracle Human Resources. Successful exploitation can lead to unauthorized creation, modification, or deletion of critical data, complete data access, and partial denial of service, with potential impact extending to other products. With a CVSS v3.0 Base Score of 9.9 (Critical), it poses significant confidentiality, integrity, and availability risks. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, the vulnerability has garnered community discussion and media coverage, indicating awareness despite not being listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1.1, <= 12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:human_resources:*:*:*:*:*:*:*:* | ||
>= 12.2.3, <= 12.2.9CPE matchmatch criteria | cpe:2.3:a:oracle:human_resources:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.