Unauthenticated Access Vulnerability in Oracle Retail Xstore Point of Service
CVE-2018-2840

7.6HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2018

Summary

An unauthenticated access vulnerability in Oracle Retail Xstore Point of Service allows attackers with network access to compromise the system. Successful exploitation requires human interaction from a user other than the attacker. This vulnerability can lead to unauthorized access to sensitive data, where attackers may gain full access to the accessible data within Oracle Retail Xstore. Furthermore, it allows unauthorized modifications to the data, including update, insert, or delete operations. Attackers may also leverage this vulnerability to cause a partial denial of service on the system, posing a significant risk to data confidentiality, integrity, and availability.

Affected Version(s)

Retail Xstore Point of Service 6.5.11

Retail Xstore Point of Service 7.0.6

Retail Xstore Point of Service 7.1.6

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.