Oracle WebCenter Sites Vulnerability in Oracle Fusion Middleware
CVE-2017-3545

8.2HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

This vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (Blob Server subcomponent) enables unauthenticated attackers with network access via HTTP to compromise the application. Exploiting the vulnerability may lead to unauthorized creation, deletion, or modification of critical data, as well as potentially granting unauthorized access to sensitive information across the affected installations. Versions impacted include 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0.

Affected Version(s)

WebCenter Sites 11.1.1.8.0

WebCenter Sites 12.2.1.0.0

WebCenter Sites 12.2.1.1.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.