Vulnerability in Oracle Business Process Management Suite by Oracle
CVE-2018-3100
9.1CRITICAL
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 18 July 2018
Summary
The vulnerability allows an unauthenticated attacker with HTTP network access to compromise the Oracle Business Process Management Suite. It enables unauthorized creation, deletion, or modification of critical data, leading to severe implications for data confidentiality and integrity. Exploitation can provide full access to all data within the suite, posing a significant threat to organizations relying on Oracle's middleware solutions. For further details, consult Oracle's security advisory and related resources.
Affected Version(s)
Business Process Management Suite 11.1.1.7.0
Business Process Management Suite 11.1.1.9.0
Business Process Management Suite 12.1.3.0.0
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved