Web Application Vulnerability in Oracle WebCenter Sites by Oracle
CVE-2017-3595

7.1HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

A vulnerability exists in the Oracle WebCenter Sites component of Oracle Fusion Middleware, specifically within its Advanced UI subcomponent. This issue could allow an attacker with low privileges and network access via HTTP to exploit the system. Successful exploitation can lead to unauthorized access to sensitive data, full control over all accessible content on Oracle WebCenter Sites, and the ability to execute unauthorized updates, insertions, or deletions of data. Organizations using versions 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0, or 12.2.1.2.0 of Oracle WebCenter Sites are encouraged to mitigate the risk by applying the recommended security patches provided by Oracle.

Affected Version(s)

WebCenter Sites 11.1.1.8.0

WebCenter Sites 12.2.1.0.0

WebCenter Sites 12.2.1.1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.