| Title | Oracle Financial Services Applications における脆弱性 |
|---|---|
| Summary | Oracle Financial Services Applications には、機密性、および完全性に影響のある脆弱性が存在します。 |
| Possible impacts | リモート認証されたユーザにより、情報を取得される、および情報を改ざんされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | April 17, 2018, midnight |
| Registration Date | May 8, 2018, 2:26 p.m. |
| Last Update | May 8, 2018, 2:26 p.m. |
| CVSS3.0 : 重要 | |
| Score | 7.1 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| CVSS2.0 : 警告 | |
| Score | 5.5 |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
| オラクル |
| Oracle Banking Corporate Lending 12.3.0 |
| Oracle Banking Corporate Lending 12.4.0 |
| Oracle Banking Corporate Lending 12.5.0 |
| Oracle Banking Corporate Lending 14.0.0 |
| Oracle Banking Payments 12.3.0 |
| Oracle Banking Payments 12.4.0 |
| Oracle Banking Payments 12.5.0 |
| Oracle Banking Payments 14.0.0 |
| Oracle FLEXCUBE Enterprise Limits and Collateral Management 12.3.0 |
| Oracle FLEXCUBE Enterprise Limits and Collateral Management 14.0.0 |
| Oracle FLEXCUBE Investor Servicing 12.0.4 |
| Oracle FLEXCUBE Investor Servicing 12.1.0 |
| Oracle FLEXCUBE Investor Servicing 12.3.0 |
| Oracle FLEXCUBE Investor Servicing 12.4.0 |
| Oracle FLEXCUBE Universal Banking 11.3.0 |
| Oracle FLEXCUBE Universal Banking 11.4.0 |
| Oracle FLEXCUBE Universal Banking 12.0.1 |
| Oracle FLEXCUBE Universal Banking 12.0.2 |
| Oracle FLEXCUBE Universal Banking 12.0.3 |
| Oracle FLEXCUBE Universal Banking 12.1.0 |
| Oracle FLEXCUBE Universal Banking 12.2.0 |
| Oracle FLEXCUBE Universal Banking 12.3.0 |
| Oracle FLEXCUBE Universal Banking 12.4.0 |
| Oracle FLEXCUBE Universal Banking 14.0.0 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2018年05月08日] 掲載 |
May 8, 2018, 2:26 p.m. |
| Summary | Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Corporate Lending accessible data as well as unauthorized update, insert or delete access to some of Oracle Banking Corporate Lending accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N). |
|---|---|
| Publication Date | April 19, 2018, 11:29 a.m. |
| Registration Date | March 1, 2021, 7:22 p.m. |
| Last Update | Nov. 21, 2024, 1:04 p.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:oracle:banking_corporate_lending:12.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:banking_corporate_lending:12.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:banking_corporate_lending:12.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:banking_corporate_lending:14.0.0:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:oracle:banking_payments:12.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:banking_payments:12.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:banking_payments:12.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:banking_payments:14.0.0:*:*:*:*:*:*:* | |||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:a:oracle:flexcube_enterprise_limits_and_collateral_management:12.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_enterprise_limits_and_collateral_management:14.0.0:*:*:*:*:*:*:* | |||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:a:oracle:flexcube_investor_servicing:12.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_investor_servicing:12.1.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_investor_servicing:12.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_investor_servicing:12.4.0:*:*:*:*:*:*:* | |||||
| Configuration5 | or higher | or less | more than | less than | |
| cpe:2.3:a:oracle:flexcube_universal_banking:12.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_universal_banking:11.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_universal_banking:12.2.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_universal_banking:12.1.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_universal_banking:11.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_universal_banking:12.3.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_universal_banking:12.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_universal_banking:12.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_universal_banking:12.4.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:flexcube_universal_banking:14.0.0:*:*:*:*:*:*:* | |||||