User Interface Vulnerability in Oracle E-Business Suite Affecting Oracle Partner Management
CVE-2017-3280

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
27 January 2017

Summary

A security vulnerability exists in the User Interface component of Oracle Partner Management within the Oracle E-Business Suite. This vulnerability can be exploited by unauthenticated attackers with network access via HTTP, allowing for potential unauthorized operations on accessible data, including updates, inserts, or deletions. Successful exploitation requires human interaction and may affect other products besides Oracle Partner Management.

Affected Version(s)

Partner Management 12.1.1

Partner Management 12.1.2

Partner Management 12.1.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.