Vulnerability in Oracle WebCenter Sites Component of Oracle Fusion Middleware
CVE-2017-3543

8.6HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
24 April 2017

What is CVE-2017-3543?

A vulnerability exists in the Oracle WebCenter Sites component of Oracle Fusion Middleware that could be exploited by unauthenticated attackers over HTTP. This flaw allows attackers to gain unauthorized access to sensitive data and potentially manipulate the data within Oracle WebCenter Sites. The vulnerability could lead to unauthorized updates, inserts, or deletions, as well as a partial denial of service. Affected versions include 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0, highlighting the necessity for prompt action by organizations utilizing these versions.

Affected Version(s)

WebCenter Sites 11.1.1.8.0

WebCenter Sites 12.2.1.0.0

WebCenter Sites 12.2.1.1.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.