CVE-2017-3277
Oracle E-Business Suite 12.x Unconstrainted File Download
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: OAM Client). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS v3.0 Base Score 4.9 (Confidentiality impacts).
Vulnerabilidad en el componente Oracle Applications Manager de Oracle E-Business Suite (subcomponente: OAM Client). Versiones compatibles que están afectadas son 12.1.3, 12.2.3, 12.2.4, 12.2.5 y 12.2.6. Vulnerabilidad fácilmente explotable permite a un atacante con privilegios elevados con acceso a la red a través de HTTP, comprometer Oracle Applications Manager. Ataques exitosos de esta vulnerabilidad pueden resultar en acceso no autorizado a datos críticos o acceso completo a todos los datos accesibles de Oracle Applications Manager. CVSS v3.0 Base Score 4.9 (Impacto de Confidencialidad).
Oracle E-Business Suite versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6 suffer from an unconstrained file download vulnerability.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2016-12-06 CVE Reserved
- 2017-01-22 CVE Published
- 2023-03-08 EPSS Updated
- 2024-10-09 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/95617 | Vdb Entry | |
http://www.securitytracker.com/id/1037639 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html | 2017-02-11 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Applications Manager Search vendor "Oracle" for product "Applications Manager" | 12.1.3 Search vendor "Oracle" for product "Applications Manager" and version "12.1.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Applications Manager Search vendor "Oracle" for product "Applications Manager" | 12.2.3 Search vendor "Oracle" for product "Applications Manager" and version "12.2.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Applications Manager Search vendor "Oracle" for product "Applications Manager" | 12.2.4 Search vendor "Oracle" for product "Applications Manager" and version "12.2.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Applications Manager Search vendor "Oracle" for product "Applications Manager" | 12.2.5 Search vendor "Oracle" for product "Applications Manager" and version "12.2.5" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Applications Manager Search vendor "Oracle" for product "Applications Manager" | 12.2.6 Search vendor "Oracle" for product "Applications Manager" and version "12.2.6" | - |
Affected
|