CVE-2018-2866: Medium severity oracle e-business suite vulnerability
Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle General Ledger accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2866?
The severity of CVE-2018-2866 is medium, with a severity value of 5.3.
Which versions of Oracle E-Business Suite are affected by CVE-2018-2866?
Versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7 of Oracle E-Business Suite are affected by CVE-2018-2866.
How can an attacker exploit CVE-2018-2866?
CVE-2018-2866 can be easily exploited by an unauthenticated attacker.
Where can I find more information about CVE-2018-2866?
You can find more information about CVE-2018-2866 on the Oracle website at http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html and on security advisory websites like SecurityFocus and SecurityTracker.
How do I fix CVE-2018-2866?
To fix CVE-2018-2866, it is recommended to apply the necessary patches and updates provided by Oracle.