CVE-2020-2597 is an easily exploitable vulnerability affecting Oracle One-to-One Fulfillment versions 12.1.1-12.1.3 and 12.2.3-12.2.9 within Oracle E-Business Suite. An unauthenticated attacker with network access via HTTPS can compromise the system, requiring user interaction to succeed. The vulnerability has a CVSS 3.0 Base Score of 4.7 (Medium) and primarily impacts data integrity, allowing unauthorized updates, inserts, or deletions of accessible data. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1.1, <= 12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:one-to-one_fulfillment:*:*:*:*:*:*:*:* | ||
>= 12.2.3, <= 12.2.9CPE matchmatch criteria | cpe:2.3:a:oracle:one-to-one_fulfillment:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.