Vulnerability in File Upload of Oracle Argus Safety by Oracle
CVE-2018-2642

6.5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

A vulnerability exists in the file upload feature of Oracle Argus Safety, which allows a low privileged attacker with network access to exploit the system. Although exploitation requires human interaction from a different user, successful attacks can lead to unauthorized updates, deletions, and access to sensitive data within Oracle Argus Safety. Furthermore, it opens the door to partial denial of service conditions. This vulnerability poses significant risks not only to Argus Safety but potentially to other interconnected applications as well.

Affected Version(s)

Argus Safety 7.x

Argus Safety 8.0.x

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.