SQL Injection Vulnerability in Oracle E-Business Suite by Oracle
CVE-2017-3549
9.1CRITICAL
Summary
This vulnerability in the Oracle Scripting component of Oracle E-Business Suite allows an unauthenticated attacker to gain network access via HTTP, enabling them to compromise Oracle Scripting. Successfully exploiting this vulnerability can lead to the unauthorized creation, deletion, or modification of critical data within Oracle Scripting. The attacker may also achieve access to sensitive information, resulting in potential data breaches. Supported affected versions include 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.
Affected Version(s)
Scripting 12.1.1
Scripting 12.1.2
Scripting 12.1.3
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved