CVE-2018-2601: High severity oracle internet directory vulnerability
Vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware (subcomponent: Oracle Directory Services Manager). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.0 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2601?
The severity of CVE-2018-2601 is high.
Which versions of Oracle Internet Directory are affected by CVE-2018-2601?
Oracle Internet Directory versions 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.3.0 are affected by CVE-2018-2601.
How can an attacker exploit CVE-2018-2601?
An attacker with network access can exploit CVE-2018-2601, but it is difficult to exploit.
What can a high privileged attacker do with CVE-2018-2601?
A high privileged attacker can perform unauthorized actions with CVE-2018-2601.
Where can I find more information about CVE-2018-2601?
You can find more information about CVE-2018-2601 at the following references: [Oracle Security Advisory](http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html), [SecurityFocus](http://www.securityfocus.com/bid/102553), [SecurityTracker](http://www.securitytracker.com/id/1040208).