CVE-2018-2864: Medium severity oracle e-business suite vulnerability
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2864?
The severity of CVE-2018-2864 is medium with a severity value of 5.3.
Which component of Oracle E-Business Suite is affected by CVE-2018-2864?
The Oracle Application Object Library component of Oracle E-Business Suite is affected by CVE-2018-2864.
What versions of Oracle E-Business Suite are affected by CVE-2018-2864?
The versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7 of Oracle E-Business Suite are affected by CVE-2018-2864.
What is the recommended action to fix CVE-2018-2864?
Apply the appropriate patch or upgrade to a non-vulnerable version according to the Oracle Security Advisory.
Where can I find more information about CVE-2018-2864?
You can find more information about CVE-2018-2864 on the Oracle Security Advisory, SecurityFocus, and SecurityTracker websites.