Vulnerability in Oracle Financial Services Applications Affects Portfolio and Attribution Components
CVE-2018-2854
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 19 April 2018
What is CVE-2018-2854?
An access control vulnerability exists in the Oracle Financial Services Basel Regulatory Capital Basic component within Oracle Financial Services Applications. This vulnerability allows unauthenticated attackers with HTTP network access to potentially compromise sensitive data stored in the system. While direct exploitation provisions for user interaction, the implications may affect other integrated products significantly. Successful exploitation could enable unauthorized actions, including updates, inserts, deletes, and reading sensitive data, posing a serious risk to operational integrity and data confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Financial Services Basel Regulatory Capital Basic 8.0.x
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved