Unauthorized Data Manipulation in Oracle Retail Applications' MICROS Retail-J Component
CVE-2018-2882

7.7HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2018

Summary

The MICROS Retail-J component within Oracle Retail Applications is susceptible to a vulnerability that allows low-privileged attackers to exploit network access via HTTP. This can lead to unauthorized creation, deletion, or modification of critical data, affecting not only MICROS Retail-J but potentially other integrated products. Attackers can leverage this flaw to compromise data integrity, highlighting significant risks for organizations using affected versions.

Affected Version(s)

MICROS Retail-J 10.2.x

MICROS Retail-J 11.0.x

MICROS Retail-J 12.0.x

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.