Vulnerability in Oracle E-Business Suite iSupport Component by Oracle
CVE-2017-3371
8.2HIGH
Summary
The vulnerability is located in the Oracle iSupport component of the Oracle E-Business Suite, affecting versions 12.1.1, 12.1.2, and 12.1.3. An unauthenticated attacker with network access via HTTP can exploit this flaw, requiring human interaction from someone other than the attacker. While primarily affecting Oracle iSupport, the implications of this vulnerability can extend to other products within the suite. Successful exploitation may grant unauthorized access to sensitive information and allow attackers to manipulate Oracle iSupport’s accessible data, leading to potential data integrity issues.
Affected Version(s)
iSupport 12.1.1
iSupport 12.1.2
iSupport 12.1.3
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved