Vulnerability in Oracle WebCenter Sites Affects Oracle Fusion Middleware
CVE-2017-3554
8.1HIGH
Summary
A vulnerability exists in the Oracle WebCenter Sites component of Oracle Fusion Middleware, specifically within the Catalog Mover subcomponent. This issue permits an attacker with low privileges and network access via HTTP to exploit the system. Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data managed by Oracle WebCenter Sites. This poses substantial risks to the confidentiality and integrity of sensitive information.
Affected Version(s)
WebCenter Sites 11.1.1.8.0
WebCenter Sites 12.2.1.0.0
WebCenter Sites 12.2.1.1.0
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved