First published: Wed Oct 17 2018(Updated: )
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Application Object Library | =12.1.3 | |
Oracle Application Object Library | =12.2.3 | |
Oracle Application Object Library | =12.2.4 | |
Oracle Application Object Library | =12.2.5 | |
Oracle Application Object Library | =12.2.6 | |
Oracle Application Object Library | =12.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3244 is considered a high-severity vulnerability due to its potential for unauthenticated exploitation.
To fix CVE-2018-3244, you should apply the latest security patch provided by Oracle for the affected versions of the application.
CVE-2018-3244 affects Oracle Application Object Library versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7.
Yes, CVE-2018-3244 can be exploited remotely by an unauthenticated attacker.
Oracle does not provide specific workarounds for CVE-2018-3244, making the application of patches the recommended solution.