Vulnerability in Oracle FLEXCUBE Investor Servicing Component
CVE-2018-3028
6.3MEDIUM
Summary
A vulnerability in the Oracle FLEXCUBE Investor Servicing component allows low privileged attackers with network access via HTTP to exploit the system. This can lead to unauthorized updates, insertions, or deletions of accessible data. Moreover, attackers may gain unauthorized read access to a subset of data and can initiate a partial denial of service affecting the availability of FLEXCUBE Investor Servicing. Supported versions that are impacted include versions 12.0.4, 12.1.0, 12.3.0, and 12.4.0.
Affected Version(s)
FLEXCUBE Investor Servicing 12.0.4
FLEXCUBE Investor Servicing 12.1.0
FLEXCUBE Investor Servicing 12.3.0
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved