Unauthenticated Vulnerability in Oracle Applications Manager of Oracle E-Business Suite
CVE-2018-3235

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

The Oracle Applications Manager, part of the Oracle E-Business Suite, is susceptible to an unauthenticated access vulnerability that can be easily exploited by attackers with network access via HTTP. While the vulnerability resides in the Oracle Applications Manager, successful exploitation can facilitate unauthorized access to critical data and allow attackers to perform unauthorized actions such as updates, inserts, or deletions of data accessible through Oracle Applications Manager. The successful attacks necessitate human interaction from a user other than the attacker, amplifying the potential impact on the security infrastructure.

Affected Version(s)

Applications Manager 12.1.3

Applications Manager 12.2.3

Applications Manager 12.2.4

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.