CVE-2018-3040: Medium severity oracle banking corporate lending vulnerability
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending. CVSS 3.0 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3040?
CVE-2018-3040 is rated as a high severity vulnerability due to its potential impact on Oracle Banking Corporate Lending applications.
How do I fix CVE-2018-3040?
To fix CVE-2018-3040, apply the latest security patches provided by Oracle for the affected versions of Oracle Banking Corporate Lending.
Which versions are affected by CVE-2018-3040?
CVE-2018-3040 affects versions 12.3.0, 12.4.0, 12.5.0, 14.0.0, and 14.1.0 of Oracle Banking Corporate Lending.
Who can exploit CVE-2018-3040?
CVE-2018-3040 can be exploited by low privileged attackers who have network access to the vulnerable system.
What component of Oracle Financial Services Applications is impacted by CVE-2018-3040?
CVE-2018-3040 impacts the Corporate Lending component of Oracle Financial Services Applications.