Vulnerability in Oracle HTTP Server of Oracle Fusion Middleware
CVE-2018-2760

5.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2018

Summary

This vulnerability affects the Oracle HTTP Server component of Oracle Fusion Middleware, specifically within the OSSL Module. It permits an unauthenticated attacker, possessing network access via HTTPS, to exploit the server. A successful exploitation could lead to unauthorized access to confidential data or the compromised integrity of all information accessible through the Oracle HTTP Server. It is imperative for organizations using affected versions—12.1.3 and 12.2.1.2—to assess their security postures and apply necessary mitigations to protect their data.

Affected Version(s)

HTTP Server 12.1.3

HTTP Server 12.2.1.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.