CVE-2020-25649 | Oracle Communications Interactive Session Recorder 6.3/6.4 Provision API xml external entity reference
A vulnerability was found in Oracle Communications Interactive Session Recorder 6.3/6.4 and classified as critical. The affected element is an unknown function of the component Provision API. Such manipulation leads to xml external entity reference.
This vulnerability is documented as CVE-2020-25649. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.