Oracle issued an emergency patch for vulnerabilities affecting several of its products that rely on the proprietary Jolt protocol. The vulnerabilities were reported by experts at ERPScan who named the set of five vulnerabilities JoltandBleed. The most critical flaw rated with the highest CVSS base score of 9.9 and even 10.0, according to the experts it may be exploited over a network without the need for a valid username and password. An attacker can exploit the vulnerabilities to gain full access to all data stored in the following ERP systems.”]
Source: https://securityaffairs.co/wordpress/65655/hacking/joltandbleed-flaws.html

