CVE-2018-3007 is a high-severity vulnerability affecting Oracle Tuxedo versions 12.1.1, 12.1.3, and 12.2.2. This flaw allows an unauthenticated attacker to gain complete access to all Oracle Tuxedo accessible data via network access through Jolt. The vulnerability has a CVSS 3.0 Base Score of 8.6, indicating a significant risk of unauthorized data disclosure. While easily exploitable with low attack complexity, there is currently no public exploit code available, nor is it listed on the CISA KEV catalog. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1.1CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.1.1:*:*:*:*:*:*:* | ||
12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.1.3:*:*:*:*:*:*:* | ||
12.2.2CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.