Vulnerability in Oracle WebCenter Sites Affects Oracle Fusion Middleware
CVE-2017-3541
8.2HIGH
Summary
A vulnerability exists in the Oracle WebCenter Sites component of Oracle Fusion Middleware that can be easily exploited by an unauthenticated attacker with network access via HTTP. This flaw allows the attacker to compromise the Oracle WebCenter Sites environment, resulting in unauthorized access to sensitive data and enabling actions such as unauthorized updates, inserts, or deletions of accessible data within Oracle WebCenter Sites. Affected versions include 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0.
Affected Version(s)
WebCenter Sites 11.1.1.8.0
WebCenter Sites 12.2.1.0.0
WebCenter Sites 12.2.1.1.0
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved