Unauthorized Access Risk in Oracle E-Business Suite's Calendar Component
CVE-2017-10322
5.3MEDIUM
What is CVE-2017-10322?
A vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite allows unauthenticated network attackers to exploit the system via HTTP. This flaw permits unauthorized operations such as data updates, insertions, or deletions within the accessible data of the Calendar component. The affected versions include 12.1.1 through 12.2.7. Organizations using these versions should obtain the necessary patches to mitigate risks of data integrity loss.
Affected Version(s)
Common Applications Calendar 12.1.1
Common Applications Calendar 12.1.2
Common Applications Calendar 12.1.3