Unauthorized Data Access in Oracle FLEXCUBE Enterprise Limits and Collateral Management
CVE-2018-3047

5.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2018

Summary

A vulnerability exists in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications that permits a low-privilege attacker with network access via HTTP to exploit the system. This can allow for unauthorized access to sensitive or critical data within the Oracle application. Affected users may face risks associated with data compromise, with attackers potentially gaining access to all accessible Oracle FLEXCUBE data. Users are advised to monitor their systems and apply available security patches to mitigate this risk.

Affected Version(s)

FLEXCUBE Enterprise Limits and Collateral Management 12.3.0

FLEXCUBE Enterprise Limits and Collateral Management 14.0.0

FLEXCUBE Enterprise Limits and Collateral Management 14.1.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.