Oracle Database Server Application Express Vulnerability
CVE-2018-2699

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

An unauthenticated attacker can exploit a weakness in the Application Express component of Oracle Database Server to achieve unauthorized access. This vulnerability allows the attacker to compromise Application Express with network access through HTTP. Although the vulnerability is contained within Application Express, successful exploitation can lead to significant consequences for other connected products. Attackers may gain unauthorized ability to read, update, insert, or delete data that is accessible through Application Express, especially requiring human interaction from a third party to trigger the attack.

Affected Version(s)

Application Express < 5.1.4.00.08

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.