CVE-2018-2888 Details
Description
Vulnerability in the MICROS Retail-J component of Oracle Retail Applications (subcomponent: Back Office). Supported versions that are affected are 10.2.x, 11.0.x, 12.0.x, 12.1.x, 12.1.1.x,12.1.2.x and 13.1.x. Difficult to exploit vulnerability allows physical access to compromise MICROS Retail-J. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MICROS Retail-J, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MICROS Retail-J accessible data as well as unauthorized access to critical data or complete access to all MICROS Retail-J accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MICROS Retail-J. CVSS 3.0 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 2, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html | CVE | PatchVendor Advisory |
| http://www.securityfocus.com/bid/104822 | CVE | |
| http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html | [email protected] | PatchVendor Advisory |
| http://www.securityfocus.com/bid/104822 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| oracle micros retail-j | 10.2 sp32 10.2 sp33 11.0 sp24 11.0 sp25 11.0 sp26 12.0 sp10 12.0 sp11 12.0 sp7 12.0 sp8 12.0 sp9 12.1 fp1_sp1 12.1 fp1_sp2 12.1 fp1_sp3 12.1 fp1_sp4 12.1 fp1_sp5 12.1 fp2_sp2 12.1 fp2_sp3 12.1 fp2_sp4 12.1 fp2_sp5 12.1 fp2_sp6 12.1 sp4 12.1 sp5 12.1 sp6 12.1 sp7 12.1 sp8 13.1.1 13.1.2 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Jul 30, 2018 | CVE Modified | [email protected] |
| Jul 24, 2018 | Initial Analysis | [email protected] |