CVE-2018-3108 is a vulnerability in the Oracle Notification Service subcomponent of Oracle Fusion Middleware versions 12.2.1.2 and 12.2.1.3. This vulnerability allows a low-privileged attacker with network access via HTTPS to gain unauthorized access to critical or all accessible data within Oracle Fusion Middleware. While difficult to exploit, successful attacks can lead to high confidentiality impacts. There is currently no public exploit code, Metasploit modules, or significant community discussion or media coverage surrounding this CVE, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2.1.2CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:12.2.1.2:*:*:*:*:*:*:* | ||
12.2.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:12.2.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.