Vulnerability in Oracle Access Manager for Oracle Fusion Middleware
CVE-2017-10262

5.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

The vulnerability within Oracle Access Manager of Oracle Fusion Middleware facilitates unauthorized access for attackers with network access via HTTPS. This security flaw does not require authentication, enabling potential intruders to compromise Oracle Access Manager and gain access to sensitive data. As a result, attackers can exploit this issue to access all data that the Oracle Access Manager can access, posing significant risks to data confidentiality.

Affected Version(s)

Access Manager 11.1.2.3.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.