Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE network
low complexity
oracle
nessus
Published: 2018-01-18
Updated: 2019-10-03
Summary
Vulnerability in the Oracle Financial Services Market Risk Measurement and Management component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Market Risk Measurement and Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Market Risk Measurement and Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Market Risk Measurement and Management accessible data as well as unauthorized read access to a subset of Oracle Financial Services Market Risk Measurement and Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Vulnerable Configurations
Part | Description | Count |
Application | Oracle | 1 |
Nessus
NASL family | CGI abuses |
NASL id | ORACLE_WEBCENTER_CONTENT_JAN_2018_CPU.NASL |
description | The version of Oracle WebCenter Content running on the remote host is affected by multiple vulnerabilities. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 107090 |
published | 2018-03-01 |
reporter | This script is Copyright (C) 2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/107090 |
title | Oracle WebCenter Content Multiple Vulnerabilities (January 2018 CPU) |