Unrestricted Access in Oracle E-Business Suite's iSupport Component
CVE-2017-3370

8.2HIGH

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
27 January 2017

Summary

The vulnerability in the Oracle iSupport component of the Oracle E-Business Suite allows an unauthenticated attacker with network access to exploit the system, potentially compromising sensitive data. Attackers may gain unauthorized access that could result in extensive data manipulation, including updating, inserting, or deleting information within Oracle iSupport. While the vulnerability specifically resides in iSupport, the implications could extend to other interconnected products, causing significant security risks.

Affected Version(s)

iSupport 12.1.1

iSupport 12.1.2

iSupport 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.