{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-20T19:16:17.502","vulnerabilities":[{"cve":{"id":"CVE-2020-8203","sourceIdentifier":"support@hackerone.com","published":"2020-07-15T17:15:11.797","lastModified":"2024-11-21T05:38:29.790","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20."},{"lang":"es","value":"Un ataque de contaminación de prototipo cuando se utiliza _.zipObjectDeep en lodash versiones anteriores a 4.17.20"}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"support@hackerone.com","type":"Secondary","description":[{"lang":"en","value":"CWE-770"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1321"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:lodash:lodash:*:*:*:*:*:node.js:*:*","versionEndExcluding":"4.17.20","matchCriteriaId":"5320B76A-C335-4F3B-A589-73CC64033FFB"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.2.0:*:*:*:*:*:*:*","matchCriteriaId":"0CF9A061-2421-426D-9854-0A4E55B2961D"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.3.0:*:*:*:*:*:*:*","matchCriteriaId":"F95EDC3D-54BB-48F9-82F2-7CCF335FCA78"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5.0:*:*:*:*:*:*:*","matchCriteriaId":"B72B735F-4E52-484A-9C2C-23E6E2070385"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.2.0:*:*:*:*:*:*:*","matchCriteriaId":"8B36A1D4-F391-4EE3-9A65-0A10568795BA"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.3.0:*:*:*:*:*:*:*","matchCriteriaId":"55116032-AAD1-4FEA-9DA8-2C4CBD3D3F61"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5.0:*:*:*:*:*:*:*","matchCriteriaId":"0275F820-40BE-47B8-B167-815A55DF578E"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_extensibility_workbench:14.2.0:*:*:*:*:*:*:*","matchCriteriaId":"8C8E145E-1DF0-4B18-B625-F04DF71F6ACF"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_extensibility_workbench:14.3.0:*:*:*:*:*:*:*","matchCriteriaId":"EABAFD73-150F-4DFE-B721-29EB4475D979"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_extensibility_workbench:14.5.0:*:*:*:*:*:*:*","matchCriteriaId":"8A45D47B-3401-49CF-92EE-79D007D802A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_liquidity_management:14.2.0:*:*:*:*:*:*:*","matchCriteriaId":"33605127-1352-4285-AE96-B51156B70613"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_liquidity_management:14.3.0:*:*:*:*:*:*:*","matchCriteriaId":"FA7423C4-7016-429B-997F-61E7AEB8F696"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_liquidity_management:14.5.0:*:*:*:*:*:*:*","matchCriteriaId":"C7BC8689-5E87-43FE-ADE8-5907F581B08E"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_supply_chain_finance:14.2.0:*:*:*:*:*:*:*","matchCriteriaId":"6A8420D4-AAF1-44AA-BF28-48EE3ED310B9"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_supply_chain_finance:14.3.0:*:*:*:*:*:*:*","matchCriteriaId":"2FB80AC5-35F2-4703-AD93-416B46972EEB"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_supply_chain_finance:14.5.0:*:*:*:*:*:*:*","matchCriteriaId":"19DAAEFF-AB4A-4D0D-8C86-D2F2811B53B1"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_trade_finance_process_management:14.2.0:*:*:*:*:*:*:*","matchCriteriaId":"9E14324D-B9EE-4C06-ACC7-255189ED6300"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_trade_finance_process_management:14.3.0:*:*:*:*:*:*:*","matchCriteriaId":"CBEBB60F-6EAB-4AE5-B777-5044C657FBA8"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5.0:*:*:*:*:*:*:*","matchCriteriaId":"B185C1EA-71E6-4972-8637-08A33CC00841"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_virtual_account_management:14.2.0:*:*:*:*:*:*:*","matchCriteriaId":"D1534C11-E3F5-49F3-8F8D-7C5C90951E69"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_virtual_account_management:14.3.0:*:*:*:*:*:*:*","matchCriteriaId":"D952E04D-DE2D-4AE0-BFE6-7D9B7E55AC80"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:banking_virtual_account_management:14.5.0:*:*:*:*:*:*:*","matchCriteriaId":"1111BCFD-E336-4B31-A87E-76C684AC6DE4"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:*","versionEndExcluding":"21.1.2","matchCriteriaId":"D0DBC938-A782-433F-8BF1-CA250C332AA7"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_billing_and_revenue_management:7.5.0.23.0:*:*:*:*:*:*:*","matchCriteriaId":"790A89FD-6B86-49AE-9B4F-AE7262915E13"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0:*:*:*:*:*:*:*","matchCriteriaId":"E39D442D-1997-49AF-8B02-5640BE2A26CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.11.0:*:*:*:*:*:*:*","matchCriteriaId":"EC7DB86F-3FAA-43C1-9C44-7CC5FB34419E"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_session_border_controller:8.4:*:*:*:*:*:*:*","matchCriteriaId":"9C416FD3-2E2F-4BBC-BD5F-F896825883F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_session_border_controller:9.0:*:*:*:*:*:*:*","matchCriteriaId":"D886339E-EDB2-4879-BD54-1800E4CA9CAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_session_border_controller:cz8.4:*:*:*:*:*:*:*","matchCriteriaId":"62A561CF-09BE-4EDB-AAB7-4B057C0B0E44"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_session_router:cz8.4:*:*:*:*:*:*:*","matchCriteriaId":"ECF63433-30CC-4E0D-B66A-FD160111763B"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_subscriber-aware_load_balancer:cz8.3:*:*:*:*:*:*:*","matchCriteriaId":"5F2BFCE3-D743-4AC6-8FEC-75CAF66BFB65"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:communications_subscriber-aware_load_balancer:cz8.4:*:*:*:*:*:*:*","matchCriteriaId":"B8D05530-BFC7-4652-B387-BC931F43AB5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:enterprise_communications_broker:3.2.0:*:*:*:*:*:*:*","matchCriteriaId":"348EEE70-E114-4720-AAAF-E77DE5C9A2D1"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:enterprise_communications_broker:3.3.0:*:*:*:*:*:*:*","matchCriteriaId":"3DCDD73B-57B1-4580-B922-5662E3AC13B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:enterprise_communications_broker:pcz3.3:*:*:*:*:*:*:*","matchCriteriaId":"4B317147-064A-4786-B3D6-CDE1653E067E"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*","versionEndIncluding":"9.2.6.0","matchCriteriaId":"9722362B-027B-4311-8F3A-287AE1199019"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*","matchCriteriaId":"D9DB4A14-2EF5-4B54-95D2-75E6CF9AA0A9"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*","matchCriteriaId":"C8AF00C6-B97F-414D-A8DF-057E6BFD8597"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"17.12.0","versionEndIncluding":"17.12.11","matchCriteriaId":"8B1C88FD-C2EC-4C96-AC7E-6F95C8763B48"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"18.8.0","versionEndIncluding":"18.8.12","matchCriteriaId":"301E7158-9090-467C-B3B4-30A8DB3B395D"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"19.12.0","versionEndIncluding":"19.12.11","matchCriteriaId":"BBEFACB1-C8EA-492B-8F85-A564DB363C83"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:primavera_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"20.12.0","versionEndIncluding":"20.12.7","matchCriteriaId":"E6B70E72-B9FC-4E49-8EDD-29C7E14F5792"}]}]}],"references":[{"url":"https://github.com/lodash/lodash/issues/4874","source":"support@hackerone.com","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/712065","source":"support@hackerone.com","tags":["Exploit","Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20200724-0006/","source":"support@hackerone.com","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","source":"support@hackerone.com","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","source":"support@hackerone.com","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","source":"support@hackerone.com","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","source":"support@hackerone.com","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","source":"support@hackerone.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/lodash/lodash/issues/4874","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Vendor Advisory"]},{"url":"https://hackerone.com/reports/712065","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20200724-0006/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]}]}}]}