Unauthenticated Network Vulnerability in Oracle Identity Manager by Oracle
CVE-2018-3179

7.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

A vulnerability exists within the Oracle Identity Manager component of Oracle Fusion Middleware, specifically in the Advanced Console. This flaw allows unauthenticated attackers with network access via HTTP to compromise the Oracle Identity Manager. Affected versions are 11.1.2.3.0 and 12.2.1.3.0. The exploitation of this vulnerability can lead to unauthorized access to sensitive data within Oracle Identity Manager and the potential to partially disrupt its services, resulting in a denial of service effect. Organizations utilizing these versions should take immediate action to mitigate the risks associated with this vulnerability.

Affected Version(s)

Identity Manager 11.1.2.3.0

Identity Manager 12.2.1.3.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.