Vulnerability in Oracle E-Business Suite's Partner Management Component
CVE-2017-3283
4.7MEDIUM
Summary
An identified vulnerability in the Oracle Partner Management component of Oracle E-Business Suite allows an unauthenticated attacker with network access via HTTP to compromise the system. It necessitates human interaction from a person who is not the attacker for successful exploitation. While the vulnerability is specifically within Oracle Partner Management, successful attacks can have a significant impact on additional products. If exploited, the unauthorized access could lead to the alteration of data within Oracle Partner Management, including the ability to update, insert, or delete sensitive information.
Affected Version(s)
Partner Management 12.1.1
Partner Management 12.1.2
Partner Management 12.1.3
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved