Unauthorized Access Risk in Oracle E-Business Suite's Calendar Component
CVE-2017-10322
5.3MEDIUM
Summary
A vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite allows unauthenticated network attackers to exploit the system via HTTP. This flaw permits unauthorized operations such as data updates, insertions, or deletions within the accessible data of the Calendar component. The affected versions include 12.1.1 through 12.2.7. Organizations using these versions should obtain the necessary patches to mitigate risks of data integrity loss.
Affected Version(s)
Common Applications Calendar 12.1.1
Common Applications Calendar 12.1.2
Common Applications Calendar 12.1.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved