Vulnerability in Oracle Financial Services Applications Fund Transfer Pricing User Interface
CVE-2018-2729

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

A vulnerability exists in the User Interface component of the Fund Transfer Pricing feature in Oracle Financial Services Applications, affecting versions 6.1.x and 8.0.x. This flaw allows a low-privileged attacker with network access via HTTP to exploit the system, leading to unauthorized operations such as the creation, deletion, or modification of crucial data. Successful exploitation can pave the way for unauthorized access to sensitive information, posing a significant risk to the integrity and confidentiality of data within the Oracle Financial Services Fund Transfer Pricing component.

Affected Version(s)

Financial Services Funds Transfer Pricing 6.1.x

Financial Services Funds Transfer Pricing 8.0.x

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.