Vulnerability in Oracle Retail Open Commerce Platform Affects Integrations
CVE-2018-3122

6.8MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

This vulnerability in the Oracle Retail Open Commerce Platform component allows low-privileged attackers with network access via HTTP to exploit the system. Successful exploitation grants unauthorized capabilities to create, delete, or modify critical data, posing a significant risk to data confidentiality and integrity across the affected versions (5.3, 6.0, and 6.0.1). As a result, sensitive information may be exposed, leading to potential data breaches if not properly mitigated.

Affected Version(s)

Retail Open Commerce Platform Cloud Service 6.0

Retail Open Commerce Platform Cloud Service 6.0.1

Retail Open Commerce Platform Cloud Service 5.3

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.