Missing authorization in Oracle Retail Predictive Application Server



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2018-1258
CWE-ID CWE-862
Exploitation vector Network
Public exploit N/A
Vulnerable software
Oracle Retail Predictive Application Server
Server applications / Application servers

Vendor Oracle

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Missing authorization

EUVDB-ID: #VU12651

Risk: Low

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2018-1258

CWE-ID: CWE-862 - Missing Authorization

Exploit availability: No

Description

The vulnerability allows a remote unauthenticated attacker to bypass security restrictions on the target system.

The weakness exists due to improper security restrictions when using Spring Security method security. A remote attacker can submit a specially crafted request, bypass authorization restrictions and gain unauthorized access to certain methods that should be restricted. 

Mitigation

Install update from vendor's website.

Vulnerable software versions

Oracle Retail Predictive Application Server: 14.0.3.26 - 15.0.3.100

CPE2.3 External links

https://www.oracle.com/security-alerts/cpujul2019.html?534496


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###