Oracle E-Business Suite User Interface Vulnerability in Universal Work Queue
CVE-2017-3416

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
27 January 2017

Summary

A vulnerability exists in the Oracle Universal Work Queue component of Oracle E-Business Suite, allowing unauthenticated attackers with HTTP network access to compromise the system. While the vulnerability is contained within the Oracle Universal Work Queue, successful exploitation can have serious implications for additional products. It requires human interaction from a third party, which could lead to unauthorized access and manipulation of sensitive data. This includes enabling unauthorized updates, inserts or deletions to data accessible via the Oracle Universal Work Queue, ultimately jeopardizing the confidentiality and integrity of the information.

Affected Version(s)

Universal Work Queue 12.1.1

Universal Work Queue 12.1.2

Universal Work Queue 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.