User Interface Vulnerability in Oracle E-Business Suite
CVE-2017-3361

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
27 January 2017

Summary

The vulnerability in the Oracle Installed Base component of Oracle E-Business Suite allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation of this issue can enable unauthorized access to sensitive data, potentially resulting in full access to all accessible data within the Installed Base. This exploitation necessitates human interaction from another individual, making successful attacks reliant on specific user actions. While the vulnerability is localized within the Installed Base component, the repercussions of successful attacks may extend to other connected products, jeopardizing the integrity of the overall system.

Affected Version(s)

Installed Base 12.1.1

Installed Base 12.1.2

Installed Base 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.