Oracle Support Tools ASR Component Vulnerability
CVE-2017-3233
7.5HIGH
Summary
An improper access control vulnerability exists in the Automatic Service Request (ASR) component of Oracle Support Tools, affecting versions prior to 5.7. This flaw allows an unauthenticated attacker with network access via HTTP to manipulate ASR functionality. Attacks can lead to unauthorized creation, deletion, or modification of critical ASR data, posing significant risks to data integrity.
Affected Version(s)
Automatic Service Request (ASR) < 5.7
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved