Vulnerability in Oracle FLEXCUBE Enterprise Limits and Collateral Management
CVE-2017-3490

3.1LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

A vulnerability exists in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications. This issue permits a low privileged attacker with network access via HTTP to potentially gain unauthorized read access to certain sensitive data stored within the system. The affected versions, 12.0.0 and 12.1.0, require prompt action to mitigate the risk of exploitation and protect sensitive information.

Affected Version(s)

FLEXCUBE Enterprise Limits and Collateral Management 12.0.0

FLEXCUBE Enterprise Limits and Collateral Management 12.1.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.