Vulnerability in Oracle WebCenter Sites Component of Oracle Fusion Middleware
CVE-2017-3593

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

This vulnerability affects the Oracle WebCenter Sites component of Oracle Fusion Middleware, enabling unauthenticated attackers with network access via HTTP to potentially compromise the system. While exploitation necessitates human interaction from a victim, successful attacks can lead to unauthorized access to sensitive data, manipulation capabilities such as updates, inserts, or deletions, and full exposure of accessible data within Oracle WebCenter Sites. Organizations utilizing the affected versions should prioritize implementing security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

WebCenter Sites 11.1.1.8.0

WebCenter Sites 12.2.1.0.0

WebCenter Sites 12.2.1.1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.