PT-2018-15847 · Oracle · Oracle Data Visualization Desktop
Published
2018-04-19
·
Updated
2019-10-03
·
CVE-2018-2834
CVSS v3.1
8.5
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Oracle Data Visualization Desktop version 12.2.4.1.1
Description
The issue allows an unauthenticated attacker with logon to the infrastructure where Oracle Data Visualization Desktop executes to compromise Oracle Data Visualization Desktop. Successful attacks require human interaction from a person other than the attacker. Attacks may significantly impact additional products and can result in unauthorized creation, deletion, or modification access to critical data, as well as unauthorized read access to a subset of Oracle Data Visualization Desktop accessible data. Additionally, attacks can cause a hang or frequently repeatable crash of Oracle Data Visualization Desktop.
Recommendations
For Oracle Data Visualization Desktop version 12.2.4.1.1, refer to My Oracle Support Note 2384640.1 for instructions on how to address this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Data Visualization Desktop