製品・ソフトウェアに関する情報
Oracle Retail Applications の Oracle Retail Integration Bus における RIB Kernal(Apache Commons Collections) に関する脆弱性
Title Oracle Retail Applications の Oracle Retail Integration Bus における RIB Kernal(Apache Commons Collections) に関する脆弱性
Summary

Oracle Retail Applications の Oracle Retail Integration Bus には、RIB Kernal(Apache Commons Collections) に関する処理に不備があるため、機密性、完全性、および可用性に影響のある脆弱性が存在します。

Possible impacts リモートの攻撃者により、情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 攻撃が行われる可能性があります。
Solution

ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。

Publication Date April 17, 2018, midnight
Registration Date May 8, 2018, 11:36 a.m.
Last Update May 8, 2018, 11:36 a.m.
CVSS3.0 : 重要
Score 7.1
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CVSS2.0 : 警告
Score 6.8
Vector AV:N/AC:M/Au:N/C:P/I:P/A:P
Affected System
オラクル
Oracle Retail Integration Bus 13.2
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
No Changed Details Date of change
1 [2018年05月08日]
  掲載
May 8, 2018, 11:36 a.m.

NVD Vulnerability Information
CVE-2018-2876
Summary

Vulnerability in the Oracle Retail Integration Bus component of Oracle Retail Applications (subcomponent: RIB Kernal(Apache Commons Collections)). The supported version that is affected is 13.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Integration Bus, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Integration Bus accessible data as well as unauthorized read access to a subset of Oracle Retail Integration Bus accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Integration Bus. CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).

Publication Date April 19, 2018, 11:29 a.m.
Registration Date March 1, 2021, 7:23 p.m.
Last Update Nov. 21, 2024, 1:04 p.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:oracle:retail_integration_bus:13.2:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List