Unauthorized Data Access in Oracle E-Business Suite General Ledger
CVE-2018-2656
9.1CRITICAL
Summary
The vulnerability in the Oracle General Ledger component of Oracle E-Business Suite allows an unauthenticated attacker with network access via HTTP to manipulate sensitive data. Affected versions are vulnerable to unauthorized creation, deletion, or modification of data, compromising the integrity and confidentiality of critical data. Attackers might gain complete access to all data managed by the Oracle General Ledger, creating severe repercussions for data security.
Affected Version(s)
General Ledger 12.1.1
General Ledger 12.1.2
General Ledger 12.1.3
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved