Unauthorized Data Manipulation in Oracle Retail Applications' MICROS Retail-J Component
CVE-2018-2882
7.7HIGH
Summary
The MICROS Retail-J component within Oracle Retail Applications is susceptible to a vulnerability that allows low-privileged attackers to exploit network access via HTTP. This can lead to unauthorized creation, deletion, or modification of critical data, affecting not only MICROS Retail-J but potentially other integrated products. Attackers can leverage this flaw to compromise data integrity, highlighting significant risks for organizations using affected versions.
Affected Version(s)
MICROS Retail-J 10.2.x
MICROS Retail-J 11.0.x
MICROS Retail-J 12.0.x
References
CVSS V3.1
Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved