CVE-2020-2750 is an easily exploitable vulnerability in the Account Hierarchy Manager component of Oracle General Ledger, affecting versions 12.1.1-12.1.3 and 12.2.3-12.2.9 of Oracle E-Business Suite. An unauthenticated attacker can exploit this via HTTP network access. This vulnerability has a CVSS 3.0 Base Score of 7.5 (High), indicating a significant risk. Successful exploitation leads to unauthorized access to critical or all data within Oracle General Ledger, with no integrity or availability impact. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has received minimal community discussion or media coverage, suggesting it is not actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.1.1, <= 12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:general_ledger:*:*:*:*:*:*:*:* | ||
>= 12.2.3, <= 12.2.9CPE matchmatch criteria | cpe:2.3:a:oracle:general_ledger:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.