Oracle E-Business Suite Vulnerability in User Management Component
CVE-2018-2684

4.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

A vulnerability in the Oracle User Management component allows attackers with high privileges and network access via HTTP to exploit flaws in the registration process. This easily exploitable vulnerability can provide unauthorized access to sensitive data and potentially grant the attacker full control over all accessible information within Oracle User Management modules. It is crucial for organizations to apply the necessary security updates to safeguard their systems and data from potential breaches.

Affected Version(s)

User Management 12.1.3

User Management 12.2.3

User Management 12.2.4

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.