Vulnerability in Oracle Financial Services Applications Allows Unauthorized Access
CVE-2018-2855

8.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2018

Summary

An improper access control vulnerability exists in the Portfolio, Attribution component of Oracle Financial Services Basel Regulatory Capital Basic. This flaw can be exploited by attackers with low privileges and HTTP network access, allowing them to perform unauthorized actions. Exploitation may lead to the creation, deletion, or modification of critical data, impacting the confidentiality and integrity of all accessible data within the application.

Affected Version(s)

Financial Services Basel Regulatory Capital Basic 8.0.x

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.