Vulnerability in Oracle Banking Corporate Lending Component of Oracle Financial Services Applications
CVE-2018-2709

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

The vulnerability affects the Oracle Banking Corporate Lending component within Oracle Financial Services Applications. It involves improper access control that potentially allows low-privileged attackers, who have network access via HTTP, to exploit this flaw. Successful exploitation can lead to unauthorized access to sensitive and critical information, jeopardizing the security of the Oracle Banking Corporate Lending systems. This impacts the confidentiality of the accessible data, requiring immediate attention to mitigate risks associated with potential data breaches. For more details, refer to the Oracle security advisory.

Affected Version(s)

Banking Corporate Lending 12.3.0

Banking Corporate Lending 12.4.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.