High severity8.0NVD Advisory· Published Jan 18, 2018· Updated Jun 17, 2026
CVE-2018-2601
CVE-2018-2601
Description
Vulnerability in the Oracle Internet Directory component of Oracle Fusion Middleware (subcomponent: Oracle Directory Services Manager). Supported versions that are affected are 11.1.1.7.0, 11.1.1.9.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.0 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Affected products
211.1.1.7.0, 11.1.1.9.0, 12.2.1.3.0+ 1 more
- (no CPE)range: 11.1.1.7.0, 11.1.1.9.0, 12.2.1.3.0
- (no CPE)range: 11.1.1.7.0
Patches
Vulnerability mechanics
References
3- www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/102553nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1040208nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.