← Back to browse · API

CVE-2020-2791

Severity
CRITICAL
CVSS
9.8
EPSS
0.02129
Risk score
39.95
CISA KEV
No
PoC
No
Published
2020-04-15
Modified
2024-09-30
First seen
2026-08-07
Aliases
EUVD-2020-22584, GHSA-MQF4-7V67-32HM
Products
Oracle Corporation:Knowledge 8.6.0-8.6.2
Sources
euvd EUVD-2020-22584

Description

Vulnerability in the Oracle Knowledge product of Oracle Knowledge (component: Information Manager Console). Supported versions that are affected are 8.6.0-8.6.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Knowledge. Successful attacks of this vulnerability can result in takeover of Oracle Knowledge. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

References