Vulnerability in Oracle FLEXCUBE Enterprise Limits and Collateral Management
CVE-2017-3490
3.1LOW
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 24 April 2017
Summary
A vulnerability exists in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications. This issue permits a low privileged attacker with network access via HTTP to potentially gain unauthorized read access to certain sensitive data stored within the system. The affected versions, 12.0.0 and 12.1.0, require prompt action to mitigate the risk of exploitation and protect sensitive information.
Affected Version(s)
FLEXCUBE Enterprise Limits and Collateral Management 12.0.0
FLEXCUBE Enterprise Limits and Collateral Management 12.1.0
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved