Vulnerability in Oracle Retail Customer Management Component
CVE-2018-3315

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
23 July 2019

Summary

A vulnerability exists in the Oracle Retail Customer Management and Segmentation Foundation that enables a low privileged attacker with HTTP network access to compromise the system. While specifically affecting versions 16.0 and 17.0, this vulnerability can have wide-reaching impacts on associated products within the Oracle Retail Applications suite. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, thereby jeopardizing the confidentiality and integrity of the entire dataset accessible through the Oracle Retail Customer Management and Segmentation Foundation.

Affected Version(s)

Retail Customer Management and Segmentation Foundation 16.0

Retail Customer Management and Segmentation Foundation 17.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.