CVE-2018-2592 is a high-severity vulnerability affecting the User Interface subcomponent of Oracle Financial Services Balance Sheet Planning, specifically version 8.0.x. A low-privileged attacker can exploit this over HTTP to gain unauthorized read and write access to critical or all accessible data within the application. With a CVSS 3.0 Base Score of 8.1, the attack requires no user interaction and has low attack complexity, leading to high confidentiality and integrity impacts. There is currently no public exploit intelligence, such as Metasploit or ExploitDB modules, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.0.0.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:financial_services_balance_sheet_planning:8.0.0.0.0:*:*:*:*:*:*:* | ||
8.0.1.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:financial_services_balance_sheet_planning:8.0.1.0.0:*:*:*:*:*:*:* | ||
8.0.2.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:financial_services_balance_sheet_planning:8.0.2.0.0:*:*:*:*:*:*:* | ||
8.0.5.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:financial_services_balance_sheet_planning:8.0.5.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.