CVE-2018-2872: Medium severity oracle e-business suite vulnerability
Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle General Ledger accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-2872?
CVE-2018-2872 is a vulnerability in the Oracle General Ledger component of Oracle E-Business Suite, specifically the Account Hierarchy Manager subcomponent.
Which versions of Oracle E-Business Suite are affected by CVE-2018-2872?
CVE-2018-2872 affects versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7 of Oracle E-Business Suite.
How severe is CVE-2018-2872?
CVE-2018-2872 has a severity rating of medium with a CVSS score of 5.3.
How can CVE-2018-2872 be exploited?
CVE-2018-2872 can be exploited by an unauthenticated attacker.
Where can I find more information about CVE-2018-2872?
More information about CVE-2018-2872 can be found on the Oracle Security Advisory (http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html), SecurityFocus (http://www.securityfocus.com/bid/103865), and SecurityTracker (http://www.securitytracker.com/id/1040694) websites.