CVE-2018-2648: High severity oracle flexcube universal banking vulnerability
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Universal Banking. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2648?
The severity of CVE-2018-2648 is high with a severity value of 8.8.
Which versions of Oracle FLEXCUBE Universal Banking are affected by CVE-2018-2648?
The affected versions of Oracle FLEXCUBE Universal Banking are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, and 12.4.0.
How can CVE-2018-2648 be exploited?
CVE-2018-2648 can be easily exploited, allowing low privilege attackers to compromise the system.
Is there a fix available for CVE-2018-2648?
Yes, Oracle has released patches to address the vulnerability. It is recommended to apply the necessary updates.
Where can I find more information about CVE-2018-2648?
You can find more information about CVE-2018-2648 on the Oracle Security Advisory (CPUJan2018-3236628) and SecurityFocus websites.