CVE-2018-2971

4 documents4 sources
Severity
4.3MEDIUM
EPSS
0.2%
top 55.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateMay 13

Description

Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: REST Services). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.0

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jm75-qhvr-wgfh: Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: REST Services)2022-05-13
CVEList
CVE-2018-2971: Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: REST Services)2018-10-17

💬Community

1
Bugzilla
CVE-2018-20593 mxml: Stack-based buffer overflow in the scan_file function in mxmldoc.c.2018-12-31
CVE-2018-2971 (MEDIUM CVSS 4.3) | Vulnerability in the Oracle Applica | cvebase.io