Unauthenticated Access Vulnerability in Oracle Banking Corporate Lending
CVE-2018-2895

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2018

Summary

The vulnerability in Oracle Banking Corporate Lending allows an unauthenticated attacker with network access via HTTP to potentially compromise sensitive components of Oracle Financial Services Applications. Despite being specifically within the core module, successful exploitation could lead to unauthorized data manipulation such as updates, inserts, or deletes. Moreover, it permits unauthorized read access to certain accessible data. To achieve a successful attack, human interaction from a non-attacker is required, highlighting a unique attack vector that impacts not just the affected product but may extend to related applications within the Oracle suite.

Affected Version(s)

Banking Corporate Lending 12.3.0

Banking Corporate Lending 12.4.0

Banking Corporate Lending 12.5.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.