Unauthorized Access Vulnerability in Oracle E-Business Suite User Interface
CVE-2017-3440

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
27 January 2017

Summary

A vulnerability exists in the Oracle Customer Interaction History component of Oracle E-Business Suite, enabling an unauthenticated attacker to exploit the system through HTTP network access. While this vulnerability directly affects the Customer Interaction History module, its exploitation may have broader consequences on additional products within the suite. Successful exploitation typically requires human interaction from an individual other than the attacker, but can lead to unauthorized access to sensitive data, alongside the potential for unauthorized updates, insertions, and deletions of data accessible via the Oracle Customer Interaction History. This situation poses serious risks regarding the confidentiality and integrity of critical information.

Affected Version(s)

Customer Interaction History 12.1.1

Customer Interaction History 12.1.2

Customer Interaction History 12.1.3

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.