Vulnerability in Oracle Banking Corporate Lending Component of Oracle Financial Services Applications
CVE-2018-3046

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2018

Summary

A vulnerability exists in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications, allowing low-privileged attackers with network access via HTTP to compromise the system. This potentially exposes critical data, leading to unauthorized data access within Oracle Banking Corporate Lending. The impact includes the ability to view sensitive information without sufficient privileges, creating significant risks for customers relying on this application.

Affected Version(s)

Banking Corporate Lending 12.3.0

Banking Corporate Lending 12.4.0

Banking Corporate Lending 12.5.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.