Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-3246


Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).


Published

2018-10-17T01:31:26.167

Last Modified

2024-11-21T04:05:31.300

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oracle banking_platform 2.6.0 Yes
Application oracle banking_platform 2.6.1 Yes
Application oracle banking_platform 2.6.2 Yes
Application oracle business_process_management_suite 11.1.1.9.0 Yes
Application oracle business_process_management_suite 12.1.3.0.0 Yes
Application oracle business_process_management_suite 12.2.1.3.0 Yes
Application oracle communications_converged_application_server < 7.0.0.1 Yes
Application oracle communications_webrtc_session_controller < 7.2 Yes
Application oracle enterprise_repository 12.1.3.0.0 Yes
Application oracle retail_convenience_and_fuel_pos_software 2.8.1 Yes
Application oracle utilities_network_management_system 1.12.0.3 Yes
Application oracle utilities_network_management_system 2.3.0.0 Yes
Application oracle utilities_network_management_system 2.3.0.1 Yes
Application oracle utilities_network_management_system 2.3.0.2 Yes
Application oracle webcenter_portal 11.1.1.9.0 Yes
Application oracle webcenter_portal 12.2.1.3.0 Yes
Application oracle weblogic_server 12.1.3.0.0 Yes
Application oracle weblogic_server 12.2.1.3 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes

References