Vulnerability in Oracle Banking Corporate Lending Component of Oracle Financial Services Applications
CVE-2018-2707

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

A vulnerability exists in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications, affecting versions 12.3.0 and 12.4.0. This issue allows a low-privileged attacker with network access via HTTP to exploit the system, potentially leading to unauthorized creation, deletion, or modification of critical data. Additionally, successful exploitation may result in a denial-of-service condition, causing the application to hang or crash repeatedly. This vulnerability could seriously disrupt access to essential banking services and impact data integrity.

Affected Version(s)

Banking Corporate Lending 12.3.0

Banking Corporate Lending 12.4.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.