First published: Thu Oct 19 2017(Updated: )
Vulnerability in the Oracle Identity Manager Connector component of Oracle Fusion Middleware (subcomponent: Microsoft Active Directory). The supported version that is affected is 9.1.1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager Connector. CVSS 3.0 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Identity Manager Connector | =9.1.1.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10270 has a high severity due to its potential for exploitation by unauthenticated attackers.
To mitigate CVE-2017-10270, apply the recommended patches provided by Oracle for version 9.1.1.5.0.
CVE-2017-10270 affects users of Oracle Identity Manager Connector version 9.1.1.5.0.
CVE-2017-10270 can be exploited by attackers to gain unauthorized access to systems using Oracle Identity Manager Connector.
Currently, the best response for CVE-2017-10270 is to apply the patches from Oracle, as there are no known effective workarounds.