Unauthenticated Access Vulnerability in Oracle E-Business Suite by Oracle
CVE-2017-10066
5.3MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 October 2017
Summary
A vulnerability exists in the Oracle Applications Technology Stack component of Oracle E-Business Suite, specifically within Oracle Forms. This flaw can be easily exploited by an unauthenticated attacker who has network access via HTTP. Such exploitation may lead to unauthorized updates, insertions, or deletions of data within the Oracle Applications Technology Stack. Organizations utilizing the affected versions should take immediate action to safeguard their systems against potential manipulation of sensitive data.
Affected Version(s)
E-Business Suite Technology Stack 12.1.3
E-Business Suite Technology Stack 12.2.3
E-Business Suite Technology Stack 12.2.4
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved