Vulnerability in Oracle Financial Services Applications Payments Core Component
CVE-2018-3025

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2018

Summary

A vulnerability exists in the Oracle Banking Payments component of Oracle Financial Services Applications, specifically in the Payments Core subcomponent. This vulnerability allows attackers with low privileges and network access via HTTP to compromise the security of Oracle Banking Payments. Successful exploitation may lead to unauthorized access to sensitive data, with attackers potentially gaining access to all accessible Oracle Banking Payments data. Supported versions affected include 12.2.0, 12.3.0, 12.4.0, 12.5.0, and 14.1.0. Organizations using these versions should take immediate steps to mitigate the risks associated with this vulnerability.

Affected Version(s)

Banking Payments 12.2.0

Banking Payments 12.3.0

Banking Payments 12.4.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.