User Interface Vulnerability in Oracle Financial Services Applications
CVE-2018-2724

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

A vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning component permits low-privileged attackers with HTTP network access to exploit the system. This may allow unauthorized creation, deletion, or modification of critical data. Successful exploitation could lead to significant data breaches, granting attackers access to sensitive information within the platform.

Affected Version(s)

Financial Services Loan Loss Forecasting and Provisioning 8.0.x

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.