Unauthenticated Access Vulnerability in Oracle E-Business Suite Customer Interaction History
CVE-2018-3189

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

The vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation requires human interaction from a third party, but successful attacks can lead to unauthorized access to sensitive data. The impact extends beyond the Customer Interaction History component, potentially affecting other integrated systems. Attackers could gain the ability to update, insert, or delete data, presenting a serious threat to data confidentiality and integrity.

Affected Version(s)

Customer Interaction History 12.1.1

Customer Interaction History 12.1.2

Customer Interaction History 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.