Unauthorized Access Vulnerability in Oracle FLEXCUBE Core Banking by Oracle
CVE-2018-2807
6.1MEDIUM
Summary
The vulnerability exists within Oracle FLEXCUBE Core Banking, enabling unauthenticated attackers with network access via HTTP to compromise the system. Successful exploitation necessitates human interaction from a third-party individual, potentially leading to unauthorized access to sensitive data. Attackers could execute unauthorized updates, insertions, or deletions of data, in turn affecting the confidentiality and integrity of the information stored in Oracle FLEXCUBE Core Banking. The significant impact on associated data necessitates immediate attention from users of the affected versions.
Affected Version(s)
FLEXCUBE Core Banking 11.5.0
FLEXCUBE Core Banking 11.6.0
FLEXCUBE Core Banking 11.7.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved