Vulnerability in Oracle Support Tools ASR Component Affects Versions Prior to 5.7
CVE-2017-3620
7.8HIGH
Summary
A vulnerability exists within the Automatic Service Request (ASR) component of Oracle Support Tools that allows low privileged attackers with access to the execution environment of ASR to compromise its functionality. Specifically, this can lead to the takeover of the ASR system, potentially jeopardizing the confidentiality, integrity, and availability of data handled by the ASR Manager. Users are advised to upgrade to supported versions to mitigate this risk.
Affected Version(s)
Automatic Service Request (ASR) < 5.7
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved