First published: Wed Jul 18 2018(Updated: )
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.3.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle FLEXCUBE Enterprise Limits and Collateral Management | =12.3.0 | |
Oracle FLEXCUBE Enterprise Limits and Collateral Management | =14.0.0 | |
Oracle FLEXCUBE Enterprise Limits and Collateral Management | =14.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3039 is rated as a high severity vulnerability due to its ease of exploitation by unauthenticated attackers.
To fix CVE-2018-3039, update Oracle FLEXCUBE Enterprise Limits and Collateral Management to the latest available version.
CVE-2018-3039 affects Oracle FLEXCUBE versions 12.3.0, 14.0.0, and 14.1.0.
Yes, CVE-2018-3039 can be easily exploited remotely by an unauthenticated attacker.
CVE-2018-3039 affects the Infrastructure component of the Oracle FLEXCUBE Enterprise Limits and Collateral Management.