CVE-2018-2699 is a medium-severity vulnerability affecting Oracle Application Express versions prior to 5.1.4.00.08. This flaw allows an unauthenticated attacker with network access via HTTP to compromise the application, requiring user interaction to succeed. Successful exploitation can lead to unauthorized modification or deletion of some Application Express data, as well as unauthorized read access to a subset of that data. While the CVSS 3.0 base score is 6.1, there is no known public exploit code, Metasploit modules, or evidence of active exploitation. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.1.4.00.08CPE matchmatch criteria | cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:* | ||
< 5.1.4.00.08CPE match | cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.