CVE-2018-3303: Medium severity oracle enterprise manager vulnerability
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite (subcomponent: EM Console). Supported versions that are affected are 13.2 and 13.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Enterprise Manager Base Platform accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3303?
CVE-2018-3303 is classified as a high-severity vulnerability due to its ease of exploitation and potential impact.
How do I fix CVE-2018-3303?
To fix CVE-2018-3303, update your Oracle Enterprise Manager Base Platform to the latest patched versions 13.2 or 13.3.
Who is affected by CVE-2018-3303?
CVE-2018-3303 affects users of Oracle Enterprise Manager Base Platform versions 13.2 and 13.3.
What type of attack is possible with CVE-2018-3303?
CVE-2018-3303 allows an unauthenticated attacker with network access to HTTP to exploit the vulnerability.
What components are involved in CVE-2018-3303?
CVE-2018-3303 specifically involves the Enterprise Manager Base Platform component of Oracle Enterprise Manager Products Suite.