Vulnerability in Oracle JDeveloper Affecting Oracle Fusion Middleware
CVE-2018-2711
8.2HIGH
Summary
A vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware allows unauthenticated attackers to exploit the system. This issue particularly affects versions 11.1.1.2.4, 11.1.1.7.0, 11.1.1.7.1, 11.1.1.9.0, and 12.1.3.0.0. The attack can be executed remotely via HTTP, requiring human interaction from a third party, which may lead to unauthorized access and manipulation of critical data. Successful exploitation could allow an attacker to gain access to sensitive information and perform unauthorized operations such as updating, inserting, or deleting data within Oracle JDeveloper.
Affected Version(s)
JDeveloper 11.1.1.2.4
JDeveloper 11.1.1.7.0
JDeveloper 11.1.1.7.1
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved