Integrity and Availability Vulnerability in Oracle Supply Chain Products Suite
CVE-2016-3538

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 July 2016

Summary

An unspecified vulnerability exists in the Oracle Agile PLM component of the Oracle Supply Chain Products Suite versions 9.3.4 and 9.3.5. This flaw allows remote authenticated users to potentially compromise the integrity and availability of the system through vectors related to File Folders and Attachments. It poses a risk distinct from other vulnerabilities present in the product.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.