Oracle E-Business Suite Vulnerability in Application Object Library
CVE-2018-2864
5.3MEDIUM
Summary
An exploitable vulnerability exists in the Oracle Application Object Library component of Oracle E-Business Suite, affecting multiple versions. The flaw allows an unauthenticated attacker with network access through HTTP to gain unauthorized read access to certain data within the Oracle Application Object Library. This poses a risk as it may expose sensitive information that should be protected, making it essential for users to be aware of this vulnerability and apply necessary patches.
Affected Version(s)
Application Object Library 12.1.3
Application Object Library 12.2.3
Application Object Library 12.2.4
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved