Vulnerability in File Upload of Oracle Argus Safety by Oracle
CVE-2018-2642
6.5MEDIUM
Summary
A vulnerability exists in the file upload feature of Oracle Argus Safety, which allows a low privileged attacker with network access to exploit the system. Although exploitation requires human interaction from a different user, successful attacks can lead to unauthorized updates, deletions, and access to sensitive data within Oracle Argus Safety. Furthermore, it opens the door to partial denial of service conditions. This vulnerability poses significant risks not only to Argus Safety but potentially to other interconnected applications as well.
Affected Version(s)
Argus Safety 7.x
Argus Safety 8.0.x
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved