Oracle Automatic Service Request Vulnerability in Support Tools
CVE-2017-3234
9.8CRITICAL
What is CVE-2017-3234?
A vulnerability exists in the Automatic Service Request (ASR) component of Oracle Support Tools, impacting versions prior to 5.7. This flaw allows an unauthenticated attacker to gain network access via SFT, potentially leading to a complete compromise of the ASR system. If exploited, this vulnerability can enable unauthorized control over ASR features, significantly affecting system confidentiality, integrity, and availability. As such, organizations using impacted versions are advised to implement security measures immediately to mitigate associated risks.
Affected Version(s)
Automatic Service Request (ASR) < 5.7