Vulnerability in Oracle SSL API of Oracle Fusion Middleware
CVE-2017-10166

3.7LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 October 2017

Summary

A vulnerability exists in the Oracle Security Service component of Oracle Fusion Middleware, specifically within the Oracle SSL API. This issue allows an unauthenticated attacker to gain access through a network connection using HTTPS. Exploiting this vulnerability could permit the attacker to perform unauthorized actions, including updating, inserting, or deleting sensitive data accessible through the Oracle Security Service. The affected versions include FMW 11.1.1.9.0 and 12.1.3.0.0. For more details on this vulnerability, refer to the Oracle security advisory and related security databases.

Affected Version(s)

Security Service FMW: 11.1.1.9.0

Security Service 12.1.3.0.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.