First published: Tue Aug 08 2017(Updated: )
Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle iStore | =12.1.1 | |
Oracle iStore | =12.1.2 | |
Oracle iStore | =12.1.3 | |
Oracle iStore | =12.2.3 | |
Oracle iStore | =12.2.4 | |
Oracle iStore | =12.2.5 | |
Oracle iStore | =12.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10192 is rated as a high severity vulnerability due to its potential for exploitation by unauthenticated attackers.
To mitigate CVE-2017-10192, apply the latest patches provided by Oracle for affected versions of Oracle iStore.
CVE-2017-10192 affects Oracle iStore versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.
Yes, CVE-2017-10192 can be exploited remotely by an unauthenticated attacker through network access via HTTP.
CVE-2017-10192 impacts the Oracle iStore component specifically within the Shopping Cart subcomponent.