Unauthorized Data Access Vulnerability in Oracle E-Business Suite
CVE-2017-10324
5.3MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 October 2017
Summary
A vulnerability exists in the Oracle Applications Technology Stack component of Oracle E-Business Suite, specifically within Oracle Forms. This flaw is particularly concerning as it can be exploited by unauthenticated attackers with network access over HTTP. If successfully exploited, the vulnerability can lead to unauthorized read access to sensitive data within the Oracle Applications Technology Stack. Supported versions affected by this vulnerability include 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7.
Affected Version(s)
E-Business Suite Technology Stack 12.1.3
E-Business Suite Technology Stack 12.2.3
E-Business Suite Technology Stack 12.2.4
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved