Oracle Database Server Application Express Vulnerability
CVE-2018-2699
6.1MEDIUM
Summary
An unauthenticated attacker can exploit a weakness in the Application Express component of Oracle Database Server to achieve unauthorized access. This vulnerability allows the attacker to compromise Application Express with network access through HTTP. Although the vulnerability is contained within Application Express, successful exploitation can lead to significant consequences for other connected products. Attackers may gain unauthorized ability to read, update, insert, or delete data that is accessible through Application Express, especially requiring human interaction from a third party to trigger the attack.
Affected Version(s)
Application Express < 5.1.4.00.08
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved