First published: Thu Aug 02 2018(Updated: )
Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification Service). Supported versions that are affected are 12.2.1.2 and 12.2.1.3. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Fusion Middleware. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Fusion Middleware accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Fusion Middleware | =12.2.1.2 | |
Oracle Fusion Middleware | =12.2.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-3108 is medium.
Oracle Fusion Middleware versions 12.2.1.2 and 12.2.1.3 are affected by CVE-2018-3108.
A low privileged attacker can exploit CVE-2018-3108 by having network access via HTTPS to compromise the Oracle Fusion Middleware component.
Yes, Oracle has released patches to fix CVE-2018-3108. It is recommended to apply the patches to the affected versions of Oracle Fusion Middleware.
You can find more information about CVE-2018-3108 on the Oracle Security Advisory website, the SecurityFocus website, and the SecurityTracker website.