CVE-2018-2888 is a difficult-to-exploit vulnerability within the MICROS Retail-J component of Oracle Retail Applications, affecting versions 10.2.x through 13.1.x. Exploitation requires physical access to the system and human interaction from a non-attacker. Successful attacks can lead to unauthorized data modification, deletion, or access to critical data, and partial denial of service, with a CVSS 3.0 Base Score of 6.7 (Medium). Despite its potential impact, there is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.2CPE matchmatch criteria | cpe:2.3:a:oracle:micros_retail-j:10.2:sp32:*:*:*:*:*:* | ||
10.2CPE matchmatch criteria | cpe:2.3:a:oracle:micros_retail-j:10.2:sp33:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:oracle:micros_retail-j:11.0:sp24:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:oracle:micros_retail-j:11.0:sp25:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:oracle:micros_retail-j:11.0:sp26:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.