Oracle E-Business Suite Multiple Security Vulnerabilities
BID:104838
CVE-2018-2994 | CVE-2018-2995 | CVE-2018-3018 |Info
Oracle E-Business Suite Multiple Security Vulnerabilities
| Bugtraq ID: | 104838 |
| Class: | Unknown |
| CVE: |
CVE-2018-2995 CVE-2018-3018 CVE-2018-2994 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2018 12:00AM |
| Updated: | Jul 17 2018 12:00AM |
| Credit: | Pawan Patil of Electronic Arts and Adam Willard |
| Vulnerable: |
Oracle E-Business Suite 12.2.7 Oracle E-Business Suite 12.2.6 Oracle E-Business Suite 12.2.3 Oracle E-Business Suite 12.1.2 Oracle E-Business Suite 12.1.1 Oracle E-Business Suite 12.2.5 Oracle E-Business Suite 12.2.4 Oracle E-Business Suite 12.1.3 |
| Not Vulnerable: | |
Discussion
Oracle E-Business Suite Multiple Security Vulnerabilities
Oracle E-Business Suite is prone to multiple security vulnerabilities due to an error in the iStore.
These vulnerabilities can be exploited over the 'HTTP' protocol. The 'Shopping Cart' component is affected.
These vulnerabilities affect the following supported versions:
12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7
Oracle E-Business Suite is prone to multiple security vulnerabilities due to an error in the iStore.
These vulnerabilities can be exploited over the 'HTTP' protocol. The 'Shopping Cart' component is affected.
These vulnerabilities affect the following supported versions:
12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7
Exploit / POC
Oracle E-Business Suite Multiple Security Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle E-Business Suite Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oracle E-Business Suite Multiple Security Vulnerabilities
References:
References:
- Oracle Homepage (Oracle)
- Oracle Critical Patch Update Advisory - July 2018 (Oracle)