Security News > 2017 > October > Highly Critical Flaw (CVSS Score 10) Lets Hackers Hijack Oracle Identity Manager

2017-10-31 01:01
A highly critical vulnerability has been discovered in Oracle's enterprise identity management system that can be easily exploited by remote, unauthenticated attackers to take full control over the affected systems. The critical vulnerability tracked as CVE-2017-10151, has been assigned the highest CVSS score of 10 and is easy to exploit without any user interaction, Oracle said in its
News URL
http://feedproxy.google.com/~r/TheHackersNews/~3/pst7AeTa37k/oracle-identity-manager.html
Related news
- Critical flaw in Next.js lets hackers bypass authorization (source)
- Critical FortiSwitch flaw lets hackers change admin passwords remotely (source)
- Critical Apache Roller Vulnerability (CVSS 10.0) Enables Unauthorized Session Persistence (source)
- Critical Erlang/OTP SSH Vulnerability (CVSS 10.0) Allows Unauthenticated Code Execution (source)
- Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised (source)
- CISA warns of hackers targeting critical oil infrastructure (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-10-30 | CVE-2017-10151 | Unspecified vulnerability in Oracle Identity Manager Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). | 10.0 |