Vulnerability in Oracle Banking Payments Component of Oracle Financial Services Applications
CVE-2018-3020
6.3MEDIUM
What is CVE-2018-3020?
A vulnerability exists in the Oracle Banking Payments component that allows a low privileged attacker with network access via HTTP to exploit the system. Successful exploitation can lead to unauthorized updates, inserts, or deletions of data within Oracle Banking Payments. Additionally, attackers may gain unauthorized read access to certain sensitive data and have the potential to induce a partial denial of service, impacting the availability of the system. Versions 12.2.0, 12.3.0, 12.4.0, 12.5.0, and 14.1.0 are affected.
Affected Version(s)
Banking Payments 12.2.0
Banking Payments 12.3.0
Banking Payments 12.4.0