Vulnerability in Oracle Banking Payments Component Affecting Oracle Financial Services Applications
CVE-2018-3023
5.4MEDIUM
Summary
A flaw in the Oracle Banking Payments component of Oracle Financial Services Applications allows attackers with low privileges to exploit the system over HTTP. The vulnerability can lead to unauthorized update, insert, or delete operations on accessible data. Additionally, it poses a risk of a partial denial of service, compromising the availability of the service. This affects several versions, including 12.2.0 to 14.1.0, emphasizing the need for prompt security assessments and patching.
Affected Version(s)
Banking Payments 12.2.0
Banking Payments 12.3.0
Banking Payments 12.4.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved