CVE-2018-3021 is an easily exploitable vulnerability affecting Oracle Banking Payments versions 12.2.0 through 14.1.0. An unauthenticated attacker can gain network access via HTTP, resulting in unauthorized read access to a subset of accessible data within the component. This vulnerability has a CVSS 3.0 Base Score of 5.3 (Medium), indicating a low confidentiality impact with no integrity or availability impact. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on CISA's KEV catalog. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:banking_payments:12.2.0:*:*:*:*:*:*:* | ||
12.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:banking_payments:12.3.0:*:*:*:*:*:*:* | ||
12.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:banking_payments:12.4.0:*:*:*:*:*:*:* | ||
12.5.0CPE matchmatch criteria | cpe:2.3:a:oracle:banking_payments:12.5.0:*:*:*:*:*:*:* | ||
14.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:banking_payments:14.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.