CVE-2018-3069: Medium severity oracle agile product lifecycle management vulnerability
Vulnerability in the Oracle Agile Product Lifecycle Management for Process component of Oracle Supply Chain Products Suite (subcomponent: Installation). The supported version that is affected is 6.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-3069.
What is the title of the vulnerability?
The title of the vulnerability is 'Vulnerability in the Oracle Agile Product Lifecycle Management for Process component of Oracle Supply Chain Products Suite (subcomponent: Installation).'
What is the affected software?
The affected software is Oracle Agile Product Lifecycle Management for Process version 6.2.0.0.
What is the severity level of the vulnerability?
The severity level of the vulnerability is medium.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [Oracle Security Advisory](http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html) and [SecurityFocus](http://www.securityfocus.com/bid/104770).