CVE-2018-2867: Medium severity oracle e-business suite vulnerability
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-2867?
CVE-2018-2867 is a vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite.
What versions of Oracle E-Business Suite are affected by CVE-2018-2867?
CVE-2018-2867 affects versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7 of Oracle E-Business Suite.
How severe is CVE-2018-2867?
CVE-2018-2867 has a severity rating of 5.3 (medium).
How can an attacker exploit CVE-2018-2867?
CVE-2018-2867 can be exploited by an unauthenticated attacker with network access.
Are there any references for CVE-2018-2867?
Yes, you can find references for CVE-2018-2867 at the following links: [Reference 1](http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html), [Reference 2](http://www.securityfocus.com/bid/103862), [Reference 3](http://www.securitytracker.com/id/1040694)