Unauthorized Access Vulnerability in Oracle Enterprise Manager Products Suite
CVE-2018-2742
7.3HIGH
What is CVE-2018-2742?
An exploitable vulnerability exists in the Enterprise Manager Ops Center component of Oracle Enterprise Manager Products Suite, specifically in versions 12.2.2 and 12.3.3. This vulnerability allows unauthenticated attackers with network access via HTTP to gain unauthorized access to critical data. Successful exploitation can lead to unauthorized updates, inserts, or deletions of sensitive information, as well as unauthorized read access to specific data sets. Additionally, this vulnerability can enable attackers to execute partial denial-of-service attacks, impacting the availability of the Enterprise Manager Ops Center.
Affected Version(s)
Enterprise Manager Ops Center 12.2.2
Enterprise Manager Ops Center 12.3.3