CVE-2018-2801
Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Image Export SDK). The supported version that is affected is 8.5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.0 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L).
EPSS 3.20% · 87.2th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| oracle | outside_in_technology | 8.5.3 |
| Oracle Corporation | Outside In Technology | 8.5.3 |
Timeline
- Apr 19, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 25, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 27, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 2, 2022 EPSS Score
- Nov 5, 2022 EPSS Score
- Jan 7, 2023 EPSS Score
- Mar 10, 2023 EPSS Score
References
- http://www-01.ibm.com/support/docview.wss?uid=ibm10730703 advisory
- https://www-01.ibm.com/support/docview.wss?uid=ibm10739387 advisory
- https://www-01.ibm.com/support/docview.wss?uid=ibm10737709 advisory
- https://www-01.ibm.com/support/docview.wss?uid=ibm10737897 advisory
- https://www-01.ibm.com/support/docview.wss?uid=ibm10738765 advisory
- https://www-01.ibm.com/support/docview.wss?uid=ibm10738677 advisory
- https://www-01.ibm.com/support/docview.wss?uid=ibm10734447 advisory
- https://www-01.ibm.com/support/docview.wss?uid=ibm10737761 advisory
- https://www-01.ibm.com/support/docview.wss?uid=ibm10739391 advisory
- 1040695 vdb
- 103819 vdb
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html url
- https://nvd.nist.gov/vuln/detail/CVE-2018-2801 advisory