Vulnerability in Oracle Communications Convergence Mail Proxy Component
CVE-2017-10031

7.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
8 August 2017

Summary

A vulnerability exists in the Mail Proxy component of the Oracle Communications Convergence, impacting versions 3.0 and 3.0.1. This issue allows an unauthenticated attacker with network access via HTTP to compromise the application. Potential impacts include unauthorized read access and the ability to manipulate data, which can affect the integrity and confidentiality of the data processed by Oracle Communications Convergence. Attackers may gain unauthorized access to sensitive information or perform unauthorized actions on the data, leading to significant security risks.

Affected Version(s)

Communications Convergence 3.0

Communications Convergence 3.0.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
🍪 This website uses cookies, like every other website on the internet 😕 By using our website, you consent to the use of cookies.