Authentication Bypass Vulnerability in Oracle E-Business Suite Print Server
CVE-2018-2953

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2018

Summary

A vulnerability in the Oracle E-Business Suite's One-to-One Fulfillment component, specifically within the Print Server subcomponent, allows attackers with network access via HTTP to exploit the system without authentication. This flaw requires human interaction from an external user to initiate the attack. Although primarily associated with One-to-One Fulfillment, successful exploitation can have cascading effects, impacting a broader range of products within the Oracle suite. Attackers can gain unauthorized access to sensitive data, leading to potential data breaches and manipulation capabilities (such as unauthorized updates, inserts, or deletions) across the affected systems.

Affected Version(s)

One-to-One Fulfillment 12.1.1

One-to-One Fulfillment 12.1.2

One-to-One Fulfillment 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.