Vulnerability in Oracle JDeveloper Component of Oracle Fusion Middleware
CVE-2017-10273
4.7MEDIUM
Summary
A weakness in the Oracle JDeveloper component of Oracle Fusion Middleware allows an attacker with high-level privileges to compromise Oracle JDeveloper functionalities. The vulnerability requires human interaction from someone other than the attacker, making it particularly challenging to exploit. Despite being localized within Oracle JDeveloper, successful exploitation can have severe repercussions on other connected systems. Attackers can gain unauthorized access to modify, insert, or delete data, as well as access sensitive information and potentially trigger a partial denial of service in Oracle JDeveloper.
Affected Version(s)
JDeveloper 11.1.1.7.0
JDeveloper 11.1.1.7.1
JDeveloper 11.1.1.9.0
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved