First published: Tue Aug 08 2017(Updated: )
Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle General Ledger | =12.1.1 | |
Oracle General Ledger | =12.1.2 | |
Oracle General Ledger | =12.1.3 | |
Oracle General Ledger | =12.2.3 | |
Oracle General Ledger | =12.2.4 | |
Oracle General Ledger | =12.2.5 | |
Oracle General Ledger | =12.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10245 has been classified as a medium severity vulnerability allowing unauthenticated access.
To mitigate CVE-2017-10245, users should apply the latest security patches provided by Oracle for affected versions.
CVE-2017-10245 affects Oracle General Ledger versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.
CVE-2017-10245 allows an unauthenticated attacker to exploit vulnerabilities within the Oracle General Ledger component.
Yes, CVE-2017-10245 is characterized as easily exploitable, indicating that attackers can target it without authentication.