CVE-2018-2865: Medium severity oracle e-business suite vulnerability
Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle General Ledger accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-2865?
CVE-2018-2865 is a vulnerability in the Oracle General Ledger component of Oracle E-Business Suite.
Which versions of Oracle E-Business Suite are affected by CVE-2018-2865?
The versions affected by CVE-2018-2865 are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7.
What is the severity of CVE-2018-2865?
CVE-2018-2865 has a severity level of medium with a CVSS score of 5.3.
How can an attacker exploit CVE-2018-2865?
CVE-2018-2865 can be exploited by an unauthenticated attacker.
How can I fix CVE-2018-2865?
To fix CVE-2018-2865, it is recommended to apply the necessary patches provided by Oracle.