Description
Vulnerability in the Application Management Pack for Oracle E-Business Suite component of Oracle E-Business Suite (subcomponent: User Monitoring). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Management Pack for Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Application Management Pack for Oracle E-Business Suite accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Published: 2018-10-17
Score: 5.3 Medium
EPSS: 68.0% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.87445}

epss

{'score': 0.85759}


Wed, 02 Oct 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Oracle Application Management Pack
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2024-10-02T19:40:53.765Z

Reserved: 2017-12-15T00:00:00.000Z

Link: CVE-2018-3167

cve-icon Vulnrichment

Updated: 2024-08-05T04:43:34.813Z

cve-icon NVD

Status : Modified

Published: 2018-10-17T01:31:19.197

Modified: 2024-11-21T04:05:19.800

Link: CVE-2018-3167

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses