CVE-2020-2568 is a low-severity vulnerability in the Oracle Applications DBA component of Oracle Database Server, affecting versions 12.1.0.2, 12.2.0.1, 18c, and 19c. A low-privileged local attacker with logon access can exploit this vulnerability, requiring user interaction, to achieve unauthorized data modification (insert, update, delete) and partial denial of service. With a CVSS v3.0 score of 3.9, the impact is limited to integrity and availability. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:applications_dba:12.1.0.2:*:*:*:*:*:*:* | ||
12.2.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:applications_dba:12.2.0.1:*:*:*:*:*:*:* | ||
18cCPE matchmatch criteria | cpe:2.3:a:oracle:applications_dba:18c:*:*:*:*:*:*:* | ||
19cCPE matchmatch criteria | cpe:2.3:a:oracle:applications_dba:19c:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.