Vulnerability in Oracle Financial Services Applications Affects Portfolio and Attribution Components
CVE-2018-2854

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2018

Summary

An access control vulnerability exists in the Oracle Financial Services Basel Regulatory Capital Basic component within Oracle Financial Services Applications. This vulnerability allows unauthenticated attackers with HTTP network access to potentially compromise sensitive data stored in the system. While direct exploitation provisions for user interaction, the implications may affect other integrated products significantly. Successful exploitation could enable unauthorized actions, including updates, inserts, deletes, and reading sensitive data, posing a serious risk to operational integrity and data confidentiality.

Affected Version(s)

Financial Services Basel Regulatory Capital Basic 8.0.x

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.