User Interface Vulnerability in Oracle E-Business Suite by Oracle
CVE-2017-3366
8.2HIGH
Summary
An exploitable flaw exists in the User Interface component of Oracle Knowledge Management, part of the Oracle E-Business Suite. This vulnerability allows unauthenticated attackers with network access via HTTP to exploit the flaw, necessitating human interaction from a third party to facilitate the attack. Successful exploitation can lead to unauthorized access to confidential data and alteration of information within Oracle Knowledge Management, posing serious risks to organizational integrity and data confidentiality.
Affected Version(s)
Knowledge Management 12.1.1
Knowledge Management 12.1.2
Knowledge Management 12.1.3
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved