PT-2018-15847 · Oracle · Oracle Data Visualization Desktop

Published

2018-04-19

·

Updated

2019-10-03

·

CVE-2018-2834

CVSS v3.1

8.5

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Data Visualization Desktop version 12.2.4.1.1
Description The issue allows an unauthenticated attacker with logon to the infrastructure where Oracle Data Visualization Desktop executes to compromise Oracle Data Visualization Desktop. Successful attacks require human interaction from a person other than the attacker. Attacks may significantly impact additional products and can result in unauthorized creation, deletion, or modification access to critical data, as well as unauthorized read access to a subset of Oracle Data Visualization Desktop accessible data. Additionally, attacks can cause a hang or frequently repeatable crash of Oracle Data Visualization Desktop.
Recommendations For Oracle Data Visualization Desktop version 12.2.4.1.1, refer to My Oracle Support Note 2384640.1 for instructions on how to address this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-2834

Affected Products

Oracle Data Visualization Desktop