Unauthenticated Network Access Vulnerability in Oracle Tuxedo by Oracle
CVE-2017-10269

10CRITICAL

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
14 November 2017

Summary

A vulnerability exists in the Oracle Tuxedo component of Oracle Fusion Middleware. This flaw allows an unauthenticated attacker with network access to exploit Oracle Tuxedo through Jolt. Compromising Oracle Tuxedo can lead to unauthorized actions, including the creation, deletion, or modification of critical data. Additionally, attackers may gain unauthorized access to all data accessible through Oracle Tuxedo, potentially resulting in significant data breaches and the possibility of a partial denial of service.

Affected Version(s)

Tuxedo 11.1.1

Tuxedo 12.1.1

Tuxedo 12.1.3

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.