First published: Thu Jan 18 2018(Updated: )
Vulnerability in the Oracle Applications DBA component of Oracle E-Business Suite (subcomponent: ADPatch). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Applications DBA executes to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data. CVSS 3.0 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Applications DBA | =12.1.3 | |
Oracle Applications DBA | =12.2.3 | |
Oracle Applications DBA | =12.2.4 | |
Oracle Applications DBA | =12.2.5 | |
Oracle Applications DBA | =12.2.6 | |
Oracle Applications DBA | =12.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2580 is considered a high-severity vulnerability due to its potential for exploitation by high-privileged attackers.
To fix CVE-2018-2580, apply the latest patches provided by Oracle for the affected versions of Oracle Applications DBA.
CVE-2018-2580 affects Oracle Applications DBA versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7.
Organizations using the affected versions of Oracle E-Business Suite are at risk if high-privileged attackers gain access.
CVE-2018-2580 is an easily exploitable vulnerability that allows high-privileged attackers to compromise the infrastructure.