← Back

CVE-2017-3372

nvd nist
Published: Jan 27, 2017Modified: May 13, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Exploitability: 2.8 / Impact: 4.7
Source: NVD

Description

Vulnerability in the Oracle Interaction Blending component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Interaction Blending. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Interaction Blending, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Interaction Blending accessible data as well as unauthorized update, insert or delete access to some of Oracle Interaction Blending accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).

Affected (7)

1 product
Interaction Blending
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 12.1.1
Version 12.1.2
Version 12.1.3
Version 12.2.3
Version 12.2.4
Version 12.2.5
Version 12.2.6

References (6)

Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
Source: secalert_us@oracle.com
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.