SQL Injection Vulnerability in Oracle WebCenter Content Software
CVE-2017-10360
8.2HIGH
Summary
An exploitable vulnerability exists in the Oracle WebCenter Content component, affecting versions 11.1.1.9.0, 12.2.1.1.0, and 12.2.1.2.0. This vulnerability allows unauthenticated attackers with network access via HTTP to potentially compromise the integrity and confidentiality of data. Successful exploits may require human interaction, allowing the attacker to create, delete, or modify sensitive information within the Oracle WebCenter Content system. Moreover, these attacks can impact additional products connected to Oracle WebCenter, highlighting the importance of timely security measures.
Affected Version(s)
WebCenter Content 11.1.1.9.0
WebCenter Content 12.2.1.1.0
WebCenter Content 12.2.1.2.0
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved