CVE-2018-2873: Medium severity oracle e-business suite vulnerability
Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle General Ledger accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2873?
The severity of CVE-2018-2873 is medium with a CVSS score of 5.3.
Which versions of Oracle E-Business Suite are affected by CVE-2018-2873?
Oracle E-Business Suite versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7 are affected by CVE-2018-2873.
How can an attacker exploit CVE-2018-2873?
An unauthenticated attacker can easily exploit CVE-2018-2873.
Is authentication required for an attacker to exploit CVE-2018-2873?
No, authentication is not required for an attacker to exploit CVE-2018-2873.
Where can I find more information about CVE-2018-2873?
You can find more information about CVE-2018-2873 on the Oracle website and security advisories.