Vulnerability in Oracle Financial Services Applications User Interface
CVE-2018-2682

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

A vulnerability exists within the User Interface of the Oracle Financial Services Liquidity Risk Management, allowing unauthenticated attackers with network access via HTTP to exploit the system. Successful exploitation requires human interaction from a third-party user. This may lead to unauthorized access, permitting attackers to update, insert, or delete information, as well as unauthorized reading of data within the application's scope. While the vulnerability primarily affects the Liquidity Risk Management component, its impact could extend to other interconnected Oracle Financial Services products.

Affected Version(s)

Financial Services Liquidity Risk Management 8.0.x

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.