Remote Code Execution Vulnerability in Oracle FLEXCUBE by Oracle
CVE-2018-3030
6.5MEDIUM
Summary
Certain versions of Oracle FLEXCUBE Investor Servicing contain a vulnerability that allows low privileged attackers to exploit network access via HTTP. This vulnerability provides an opportunity for unauthorized users to disrupt the service, potentially leading to a denial of service (DoS). Attackers may cause the application to hang or crash repeatedly, significantly impacting availability. It is critical for users of the affected versions to apply the necessary patches and take precautions to mitigate these risks.
Affected Version(s)
FLEXCUBE Investor Servicing 12.0.4
FLEXCUBE Investor Servicing 12.1.0
FLEXCUBE Investor Servicing 12.3.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved