Exploitable Vulnerability in Oracle WebCenter Sites by Oracle
CVE-2017-3591

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

This vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware allows an unauthenticated attacker with network access via HTTP to potentially compromise the system. While exploitation requires human interaction from a third party, successful attacks could lead to unauthorized data creation, deletion, or modifications, impacting both confidentiality and integrity of the stored data. Furthermore, attackers may gain unauthorized read access to specific data within Oracle WebCenter Sites, underscoring the critical need for organizations to implement security measures against this vulnerability.

Affected Version(s)

WebCenter Sites 11.1.1.8.0

WebCenter Sites 12.2.1.0.0

WebCenter Sites 12.2.1.1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.