Vulnerability in Oracle Support Tools' Automatic Service Request Component
CVE-2017-3505

5.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

A vulnerability exists in the Automatic Service Request (ASR) component of Oracle Support Tools, specifically in versions prior to 5.7. This issue can be exploited by an unauthenticated attacker who has access to the infrastructure hosting ASR. Successful exploitation could allow unauthorized modifications to the ASR's data, including updates, inserts, or deletions. Additionally, it poses a risk of causing a partial denial of service, which could affect the availability of the ASR component. This highlights the critical need for organizations to apply security updates and ensure proper access controls are in place.

Affected Version(s)

Automatic Service Request (ASR) < 5.7

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.