File Upload Vulnerability in Oracle E-Business Suite by Oracle
CVE-2018-3138

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

A vulnerability exists in the file upload functionality of the Oracle Application Object Library within Oracle E-Business Suite. This weakness allows unauthenticated attackers with network access via HTTP to exploit the system, potentially leading to unauthorized access to sensitive data. Although human interaction is required for successful exploitation, the effects can ripple through multiple products within the suite. As a result, attackers might gain the ability to view, modify, or delete critical data stored within the Oracle Application Object Library. This vulnerability underscores the importance of securing file upload processes to prevent unauthorized data manipulation.

Affected Version(s)

Applications Framework 12.1.3

Applications Framework 12.2.3

Applications Framework 12.2.4

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.