Vulnerability in Oracle Financial Services Applications Affects Portfolio and Attribution Components
CVE-2018-2854
6.1MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 April 2018
Summary
An access control vulnerability exists in the Oracle Financial Services Basel Regulatory Capital Basic component within Oracle Financial Services Applications. This vulnerability allows unauthenticated attackers with HTTP network access to potentially compromise sensitive data stored in the system. While direct exploitation provisions for user interaction, the implications may affect other integrated products significantly. Successful exploitation could enable unauthorized actions, including updates, inserts, deletes, and reading sensitive data, posing a serious risk to operational integrity and data confidentiality.
Affected Version(s)
Financial Services Basel Regulatory Capital Basic 8.0.x
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved