Security readout for executives and security teams
Plain-English summary
This Oracle E-Business Suite issue can let an unauthenticated network attacker compromise One-to-One Fulfillment data through HTTP if a user interaction occurs. The main business risk is exposure of critical data and some unauthorized data changes in affected environments.
Executive priority
Treat as high priority for affected Oracle E-Business Suite environments because the issue can expose critical data without attacker authentication. Urgency depends on whether the affected HTTP service is reachable and whether patch status is confirmed.
Technical view
CVE-2020-2825 affects Oracle One-to-One Fulfillment 12.1.1 through 12.1.3, Print Server component. CVSS 8.2: network attack vector, low complexity, no privileges, user interaction required, changed scope, high confidentiality impact, low integrity impact, no availability impact.
Likely exposure
Exposure is likely limited to organizations running Oracle E-Business Suite with One-to-One Fulfillment versions 12.1.1-12.1.3, especially where HTTP access to the affected service is reachable by untrusted networks.
Exploitation context
The bundle does not show CISA KEV listing or other evidence of active exploitation. Oracle describes the issue as easily exploitable over HTTP without authentication, but requiring interaction from someone other than the attacker.
Researcher notes
No CWE is provided in the bundle, and technical root-cause details are sparse. The key constraints are unauthenticated HTTP reachability, required user interaction, changed scope, and potential impact beyond the affected component. Do not infer exploit activity from the available sources.
Mitigation direction
- Check Oracle's April 2020 CPU and current E-Business Suite guidance.
- Apply the relevant Oracle security patches or superseding updates.
- Restrict HTTP access to the affected One-to-One Fulfillment service.
- Review compensating controls if patching cannot happen immediately.
- Monitor Oracle advisories for product-specific remediation details.
Validation and detection
- Inventory Oracle One-to-One Fulfillment deployments and versions.
- Confirm whether versions 12.1.1-12.1.3 are present.
- Verify applicable Oracle CPU or superseding patches are installed.
- Check network paths exposing the affected HTTP service.
- Review logs for unusual access or data changes around the component.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2020-2825 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 8.2 (3.0)
- Known Exploited
- No
- Published
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N2.84.7Primary CVE scoreVulnerability scoring details
Base CVSS 3.0 score
8.2HighVector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://www.oracle.com/security-alerts/cpuapr2020.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
