First published: Thu Apr 19 2018(Updated: )
Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle General Ledger accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle E-Business Suite | =12.1.1 | |
Oracle E-Business Suite | =12.1.2 | |
Oracle E-Business Suite | =12.1.3 | |
Oracle E-Business Suite | =12.2.3 | |
Oracle E-Business Suite | =12.2.4 | |
Oracle E-Business Suite | =12.2.5 | |
Oracle E-Business Suite | =12.2.6 | |
Oracle E-Business Suite | =12.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-2866 is medium, with a severity value of 5.3.
Versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7 of Oracle E-Business Suite are affected by CVE-2018-2866.
CVE-2018-2866 can be easily exploited by an unauthenticated attacker.
You can find more information about CVE-2018-2866 on the Oracle website at http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html and on security advisory websites like SecurityFocus and SecurityTracker.
To fix CVE-2018-2866, it is recommended to apply the necessary patches and updates provided by Oracle.