Vulnerability in Oracle Communications Convergence Mail Proxy Component
CVE-2017-10031

7.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
8 August 2017

What is CVE-2017-10031?

A vulnerability exists in the Mail Proxy component of the Oracle Communications Convergence, impacting versions 3.0 and 3.0.1. This issue allows an unauthenticated attacker with network access via HTTP to compromise the application. Potential impacts include unauthorized read access and the ability to manipulate data, which can affect the integrity and confidentiality of the data processed by Oracle Communications Convergence. Attackers may gain unauthorized access to sensitive information or perform unauthorized actions on the data, leading to significant security risks.

Affected Version(s)

Communications Convergence 3.0

Communications Convergence 3.0.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.