Vulnerability in Oracle Retail Open Commerce Platform by Oracle
CVE-2017-3451
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 24 April 2017
Summary
A vulnerability exists in the Oracle Retail Open Commerce Platform, allowing low privileged attackers with network access via HTTP to potentially compromise system integrity. Successful exploitation requires human interaction from an individual other than the attacker, presenting a unique challenge for mitigation. Attackers may gain unauthorized access to sensitive data, including potential for unauthorized updates or deletions. The impact is significant, affecting the confidentiality and integrity of the platform's accessible data, which can also extend to other interconnected systems.
Affected Version(s)
Retail Open Commerce Platform Cloud Service 4.0
Retail Open Commerce Platform Cloud Service 5.0
Retail Open Commerce Platform Cloud Service 5.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved