Exploitable Vulnerability in Oracle WebCenter Sites by Oracle
CVE-2017-3542

8.6HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

This vulnerability in Oracle WebCenter Sites allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to sensitive data. Attackers may execute unauthorized updates, inserts, and deletions of accessible data within Oracle WebCenter Sites, and may also cause a partial denial of service. Supported affected versions include 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0.

Affected Version(s)

WebCenter Sites 11.1.1.8.0

WebCenter Sites 12.2.1.0.0

WebCenter Sites 12.2.1.1.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.