Unauthorized Access Vulnerability in Oracle FLEXCUBE Core Banking by Oracle
CVE-2018-2807

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2018

Summary

The vulnerability exists within Oracle FLEXCUBE Core Banking, enabling unauthenticated attackers with network access via HTTP to compromise the system. Successful exploitation necessitates human interaction from a third-party individual, potentially leading to unauthorized access to sensitive data. Attackers could execute unauthorized updates, insertions, or deletions of data, in turn affecting the confidentiality and integrity of the information stored in Oracle FLEXCUBE Core Banking. The significant impact on associated data necessitates immediate attention from users of the affected versions.

Affected Version(s)

FLEXCUBE Core Banking 11.5.0

FLEXCUBE Core Banking 11.6.0

FLEXCUBE Core Banking 11.7.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.