CVE-2024-20958 is a medium-severity vulnerability in Oracle Installed Base, specifically affecting the Engineering Change Order component in Oracle E-Business Suite versions 12.2.3 through 12.2.13. It allows a low-privileged attacker with network access via HTTP to gain unauthorized read and limited update/insert/delete access to some Installed Base data. While easily exploitable, successful attacks require user interaction and can impact additional products beyond Oracle Installed Base. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB) and no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.3, <= 12.2.13CPE match | cpe:2.3:a:oracle:installed_base:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.