CVE-2018-2656: Critical severity oracle e-business suite vulnerability
Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Data Manager Server). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.0 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-2656?
CVE-2018-2656 is a vulnerability in the Oracle General Ledger component of Oracle E-Business Suite.
Which versions of Oracle E-Business Suite are affected by CVE-2018-2656?
Versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7 of Oracle E-Business Suite are affected by CVE-2018-2656.
What is the severity of CVE-2018-2656?
CVE-2018-2656 has a severity rating of 9.1 (critical).
How can an attacker exploit CVE-2018-2656?
CVE-2018-2656 can be exploited by an unauthenticated attacker with network access to compromise Oracle General Ledger.
How can I fix CVE-2018-2656?
To fix CVE-2018-2656, Oracle recommends applying the patches provided in the official security advisory.