Internal Operations Vulnerability in Oracle Retail Applications
CVE-2018-3053

6.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2018

Summary

An exploitable vulnerability exists in Oracle Retail Customer Management and Segmentation Foundation that permits a low privileged attacker to gain unauthorized access via HTTP. This flaw, found in versions 16.x and 17.x, enables attackers to manipulate data within the system, allowing unauthorized updates, inserts, or deletions. Additionally, this vulnerability poses risks of causing a partial denial of service, impacting the overall availability of the application and affecting other connected products.

Affected Version(s)

Retail Customer Management and Segmentation Foundation 16.x

Retail Customer Management and Segmentation Foundation 17.x

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.