Vulnerability in Oracle E-Business Suite's Partner Management Component
CVE-2017-3283

4.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
27 January 2017

Summary

An identified vulnerability in the Oracle Partner Management component of Oracle E-Business Suite allows an unauthenticated attacker with network access via HTTP to compromise the system. It necessitates human interaction from a person who is not the attacker for successful exploitation. While the vulnerability is specifically within Oracle Partner Management, successful attacks can have a significant impact on additional products. If exploited, the unauthorized access could lead to the alteration of data within Oracle Partner Management, including the ability to update, insert, or delete sensitive information.

Affected Version(s)

Partner Management 12.1.1

Partner Management 12.1.2

Partner Management 12.1.3

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.