Vulnerabilities > CVE-2017-10360 - Unspecified vulnerability in Oracle Webcenter Content 11.1.1.9.0/12.2.1.1.0/12.2.1.2.0

047910
CVSS 8.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
oracle
nessus

Summary

Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server). Supported versions that are affected are 11.1.1.9.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized read access to a subset of Oracle WebCenter Content accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N).

Nessus

NASL familyCGI abuses
NASL idORACLE_WEBCENTER_CONTENT_OCT_2017_CPU.NASL
descriptionThe version of Oracle WebCenter Content running on the remote host is affected by an unspecified flaw in the Content Server component that allows an unauthenticated, remote attacker to impact confidentiality and integrity.
last seen2020-06-01
modified2020-06-02
plugin id103987
published2017-10-19
reporterThis script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/103987
titleOracle WebCenter Content Server Component Unspecified Issue (October 2017 CPU)