Vulnerability in the Oracle Order Management component of Oracle E-Business Suite (subcomponent: Product Diagnostic Tools). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Order Management executes to compromise Oracle Order Management. Successful attacks of this vulnerability can result in takeover of Oracle Order Management. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
History
Wed, 02 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: oracle
Published: 2018-07-18T13:00:00
Updated: 2024-10-02T20:14:32.868Z
Reserved: 2017-12-15T00:00:00
Link: CVE-2018-2954
Updated: 2024-08-05T04:36:39.066Z
Status : Modified
Published: 2018-07-18T13:29:03.053
Modified: 2024-11-21T04:04:49.920
Link: CVE-2018-2954
No data.