Vulnerability in Oracle Banking Corporate Lending Component of Oracle Financial Services Applications
CVE-2018-2709
5.3MEDIUM
Summary
The vulnerability affects the Oracle Banking Corporate Lending component within Oracle Financial Services Applications. It involves improper access control that potentially allows low-privileged attackers, who have network access via HTTP, to exploit this flaw. Successful exploitation can lead to unauthorized access to sensitive and critical information, jeopardizing the security of the Oracle Banking Corporate Lending systems. This impacts the confidentiality of the accessible data, requiring immediate attention to mitigate risks associated with potential data breaches. For more details, refer to the Oracle security advisory.
Affected Version(s)
Banking Corporate Lending 12.3.0
Banking Corporate Lending 12.4.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved