Vulnerabilities > CVE-2018-2993 - Unspecified vulnerability in Oracle Customer Relationship Management Technical Foundation
Summary
Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Preferences). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Vulnerable Configurations
Nessus
NASL family | Misc. |
NASL id | ORACLE_E-BUSINESS_CPU_JUL_2018.NASL |
description | The version of Oracle E-Business installed on the remote host is missing the July 2018 Oracle Critical Patch Update (CPU). It is, therefore, affected by multiple vulnerabilities as noted in the July 2018 Critical Patch Update advisory : - An unspecified vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite in the Print Server subcomponent, which could allow an unauthenticated, remote attacker to compromise Oracle One-to-One Fulfillment. (CVE-2018-2953) - An unspecified vulnerability in the Oracle Order Management component of Oracle E-Business Suite in the Product Diagnostic Tools subcomponent which could allow a low privileged attacker to compromise Oracle Order Management. (CVE-2018-2954) - An unspecified vulnerability in Oracle Application Object Library component of Oracle E-Business Suite which could allow an unauthenticated, remote attacker to compromise Oracle Application Object Library. (CVE-2018-2934) Additionally, Oracle E-Business is also affected by multiple additional vulnerabilities in other components and subcomponents. Note that Nessus has not tested for these issues but has instead relied only on the application |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 111161 |
published | 2018-07-20 |
reporter | This script is Copyright (C) 2018-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/111161 |
title | Oracle E-Business Multiple Vulnerabilities (July 2018 CPU) |
code |
|
References
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.securityfocus.com/bid/104833
- http://www.securityfocus.com/bid/104833
- http://www.securitytracker.com/id/1041309
- http://www.securitytracker.com/id/1041309