CVE-2018-3039: Medium severity oracle flexcube enterprise limits and collateral management vulnerability
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.3.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3039?
CVE-2018-3039 is rated as a high severity vulnerability due to its ease of exploitation by unauthenticated attackers.
How do I fix CVE-2018-3039?
To fix CVE-2018-3039, update Oracle FLEXCUBE Enterprise Limits and Collateral Management to the latest available version.
Which versions of Oracle FLEXCUBE are affected by CVE-2018-3039?
CVE-2018-3039 affects Oracle FLEXCUBE versions 12.3.0, 14.0.0, and 14.1.0.
Can CVE-2018-3039 be exploited remotely?
Yes, CVE-2018-3039 can be easily exploited remotely by an unauthenticated attacker.
What component of Oracle Financial Services Applications is vulnerable due to CVE-2018-3039?
CVE-2018-3039 affects the Infrastructure component of the Oracle FLEXCUBE Enterprise Limits and Collateral Management.