CVE-2018-2693

CVE: CVE-2018-2693
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: vm_virtualbox
Versions: 5.1.0, 5.1.2, 5.1.4, 5.1.6, 5.1.8, 5.1.10, 5.1.14, 5.1.18,
Description Language: en
Description: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Guest Additions). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102702
http://www.securitytracker.com/id/1040202

CVE-2018-2692

CVE: CVE-2018-2692
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: financial_services_asset_liability_management
Versions: 6.1.0.0.0, 6.1.0.2.2, 6.1.1.0.0, 8.0.0.0.0, 8.0.0.1.0, 8.0.1.0.0, 8.0.2.0.0, 8.0.3.0.0, 8.0.4.0.0, 8.0.5.0.0,
Description Language: en
Description: Vulnerability in the Oracle Financial Services Asset Liability Management component of Oracle Financial Services Applications (subcomponent: User Interface). Supported versions that are affected are 6.1.x and 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Asset Liability Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Asset Liability Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Asset Liability Management accessible data as well as unauthorized read access to a subset of Oracle Financial Services Asset Liability Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102621
http://www.securitytracker.com/id/1040214

CVE-2018-2691

CVE: CVE-2018-2691
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: user_management
Versions: 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7,
Description Language: en
Description: Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Proxy User Delegation). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle User Management accessible data as well as unauthorized read access to a subset of Oracle User Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102647
http://www.securitytracker.com/id/1040201

CVE-2018-2690

CVE: CVE-2018-2690
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: vm_virtualbox
Versions: 5.1.0, 5.1.2, 5.1.4, 5.1.6, 5.1.8, 5.1.10, 5.1.14, 5.1.18,
Description Language: en
Description: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102694
http://www.securitytracker.com/id/1040202

CVE-2018-2689

CVE: CVE-2018-2689
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: vm_virtualbox
Versions: 5.1.0, 5.1.2, 5.1.4, 5.1.6, 5.1.8, 5.1.10, 5.1.14, 5.1.18,
Description Language: en
Description: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102693
http://www.securitytracker.com/id/1040202

CVE-2018-2688

CVE: CVE-2018-2688
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: vm_virtualbox
Versions: 5.1.0, 5.1.2, 5.1.4, 5.1.6, 5.1.8, 5.1.10, 5.1.14, 5.1.18,
Description Language: en
Description: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102692
http://www.securitytracker.com/id/1040202

CVE-2018-2687

CVE: CVE-2018-2687
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: vm_virtualbox
Versions: 5.1.0, 5.1.2, 5.1.4, 5.1.6, 5.1.8, 5.1.10, 5.1.14, 5.1.18,
Description Language: en
Description: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102691
http://www.securitytracker.com/id/1040202

CVE-2018-2686

CVE: CVE-2018-2686
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: vm_virtualbox
Versions: 5.1.0, 5.1.2, 5.1.4, 5.1.6, 5.1.8, 5.1.10, 5.1.14, 5.1.18,
Description Language: en
Description: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102690
http://www.securitytracker.com/id/1040202

CVE-2018-2685

CVE: CVE-2018-2685
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: vm_virtualbox
Versions: 5.1.0, 5.1.2, 5.1.4, 5.1.6, 5.1.8, 5.1.10, 5.1.14, 5.1.18,
Description Language: en
Description: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102689
http://www.securitytracker.com/id/1040202

CVE-2018-2684

CVE: CVE-2018-2684
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: e-business_suite
Versions: 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7,
Description Language: en
Description: Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Registration Process). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle User Management accessible data. CVSS 3.0 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102649
http://www.securitytracker.com/id/1040201

CVE-2018-2683

CVE: CVE-2018-2683
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: hospitality_simphony
Versions: 2.7, 2.8, 2.9,
Description Language: en
Description: Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: POS). Supported versions that are affected are 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Simphony. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102544

CVE-2018-2682

CVE: CVE-2018-2682
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: financial_services_liquidity_risk_management
Versions: 8.0.0.1.0, 8.0.1.0.0, 8.0.2.0.0, 8.0.3.0.0, 8.0.4.0.0, 8.0.5.0.0,
Description Language: en
Description: Vulnerability in the Oracle Financial Services Liquidity Risk Management component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Liquidity Risk Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Liquidity Risk Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Liquidity Risk Management accessible data as well as unauthorized read access to a subset of Oracle Financial Services Liquidity Risk Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102657
http://www.securitytracker.com/id/1040214

CVE-2018-2681

CVE: CVE-2018-2681
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: peoplesoft_enterprise_human_capital_management_human_resources
Versions: 9.2,
Description Language: en
Description: Vulnerability in the PeopleSoft Enterprise HCM Human Resources component of Oracle PeopleSoft Products (subcomponent: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Human Resources accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102607
http://www.securitytracker.com/id/1040204

CVE-2018-2680

CVE: CVE-2018-2680
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: database_server
Versions: 11.2.0.4, 12.1.0.2, 12.2.0.1,
Description Language: en
Description: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java VM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102571
http://www.securitytracker.com/id/1040196

CVE-2018-2679

CVE: CVE-2018-2679
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: financial_services_profitability_management
Versions: 6.1.0.0.0, 6.1.0.2.2, 6.1.1.0.0, 8.0.0.0.0, 8.0.1.0.0, 8.0.2.0.0, 8.0.3.0.0, 8.0.4.0.0, 8.0.5.0.0,
Description Language: en
Description: Vulnerability in the Oracle Financial Services Profitability Management component of Oracle Financial Services Applications (subcomponent: User Interface). Supported versions that are affected are 6.1.x and 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Profitability Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Profitability Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Profitability Management accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102675
http://www.securitytracker.com/id/1040214

CVE-2018-2678

CVE: CVE-2018-2678
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: jdk
Versions: 1.6.0, 1.7.0, 1.8.0, 1.9.0.1,
jre
Versions: 1.6.0, 1.7.0, 1.8.0, 1.9.0.1,
jrockit
Versions: r28.3.16,
Description Language: en
Description: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102659
http://www.securitytracker.com/id/1040203
https://access.redhat.com/errata/RHSA-2018:0095
https://access.redhat.com/errata/RHSA-2018:0099
https://access.redhat.com/errata/RHSA-2018:0100
https://access.redhat.com/errata/RHSA-2018:0115
https://access.redhat.com/errata/RHSA-2018:0349
https://access.redhat.com/errata/RHSA-2018:0351
https://access.redhat.com/errata/RHSA-2018:0352
https://access.redhat.com/errata/RHSA-2018:0458
https://security.netapp.com/advisory/ntap-20180117-0001/

CVE-2018-2677

CVE: CVE-2018-2677
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: jdk
Versions: 1.6.0, 1.7.0, 1.8.0, 1.9.0.1,
jre
Versions: 1.6.0, 1.7.0, 1.8.0, 1.9.0.1,
Description Language: en
Description: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102656
http://www.securitytracker.com/id/1040203
https://access.redhat.com/errata/RHSA-2018:0095
https://access.redhat.com/errata/RHSA-2018:0099
https://access.redhat.com/errata/RHSA-2018:0100
https://access.redhat.com/errata/RHSA-2018:0115
https://access.redhat.com/errata/RHSA-2018:0349
https://access.redhat.com/errata/RHSA-2018:0351
https://access.redhat.com/errata/RHSA-2018:0352
https://access.redhat.com/errata/RHSA-2018:0458
https://security.netapp.com/advisory/ntap-20180117-0001/

CVE-2018-2676

CVE: CVE-2018-2676
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: vm_virtualbox
Versions: 5.1.0, 5.1.2, 5.1.4, 5.1.6, 5.1.8, 5.1.10, 5.1.14, 5.1.18,
Description Language: en
Description: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102699
http://www.securitytracker.com/id/1040202

CVE-2018-2675

CVE: CVE-2018-2675
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: java_advanced_management_console
Versions: 2.8,
Description Language: en
Description: Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java Advanced Management Console. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java Advanced Management Console accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102670
http://www.securitytracker.com/id/1040203
https://security.netapp.com/advisory/ntap-20180117-0001/

CVE-2018-2674

CVE: CVE-2018-2674
Published: 2018-01-18T02:29Z
Vendor: oracle
Products: flexcube_direct_banking
Versions: 12.0.2, 12.0.3,
Description Language: en
Description: Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Logoff). Supported versions that are affected are 12.0.2 and 12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Direct Banking. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Direct Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Direct Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Direct Banking accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
References:
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.securityfocus.com/bid/102686
http://www.securitytracker.com/id/1040214