User Interface Vulnerability in Oracle Financial Services Applications
CVE-2018-2724
8.1HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 18 January 2018
Summary
A vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning component permits low-privileged attackers with HTTP network access to exploit the system. This may allow unauthorized creation, deletion, or modification of critical data. Successful exploitation could lead to significant data breaches, granting attackers access to sensitive information within the platform.
Affected Version(s)
Financial Services Loan Loss Forecasting and Provisioning 8.0.x
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved