CVE-2017-10055: Medium severity iplanet web server vulnerability
Vulnerability in the Oracle iPlanet Web Server component of Oracle Fusion Middleware (subcomponent: Admin Graphical User Interface). The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iPlanet Web Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iPlanet Web Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iPlanet Web Server accessible data as well as unauthorized read access to a subset of Oracle iPlanet Web Server accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10055?
CVE-2017-10055 is considered easily exploitable and allows unauthenticated access, which poses a significant security threat.
How do I fix CVE-2017-10055?
To mitigate CVE-2017-10055, upgrade the affected Oracle iPlanet Web Server to the latest patched version.
What component of Oracle Fusion Middleware is affected by CVE-2017-10055?
CVE-2017-10055 affects the Admin Graphical User Interface of the Oracle iPlanet Web Server component.
Who is affected by CVE-2017-10055?
Organizations using Oracle iPlanet Web Server version 7.0 are at risk due to CVE-2017-10055.
Can CVE-2017-10055 be exploited remotely?
Yes, CVE-2017-10055 can be exploited remotely by an unauthenticated attacker with network access.