First published: Thu Aug 02 2018(Updated: )
Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder). Supported versions that are affected are 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Fusion Middleware MapViewer accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Fusion Middleware | =12.2.1.2 | |
Oracle Fusion Middleware | =12.2.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-3109 is medium.
The affected software for CVE-2018-3109 is Oracle Fusion Middleware versions 12.2.1.2 and 12.2.1.3.
The vulnerability in CVE-2018-3109 can be exploited by a low privileged attacker with network access via HTTP.
The fix for CVE-2018-3109 can be found in the Oracle Security Advisory CPUJul2018-4258247.
Yes, there are references available for CVE-2018-3109. You can find them at the following links: [Reference 1](http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html), [Reference 2](http://www.securityfocus.com/bid/104771), [Reference 3](http://www.securitytracker.com/id/1041310).