First published: Thu Oct 19 2017(Updated: )
Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Common Applications Calendar accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Common Applications Calendar | =12.1.1 | |
Oracle Common Applications Calendar | =12.1.2 | |
Oracle Common Applications Calendar | =12.1.3 | |
Oracle Common Applications Calendar | =12.2.3 | |
Oracle Common Applications Calendar | =12.2.4 | |
Oracle Common Applications Calendar | =12.2.5 | |
Oracle Common Applications Calendar | =12.2.6 | |
Oracle Common Applications Calendar | =12.2.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10322 has a CVSS score indicating it is a critical vulnerability that allows unauthenticated access.
To fix CVE-2017-10322, update your Oracle Common Applications Calendar to a patched version provided by Oracle.
The affected versions of Oracle Common Applications Calendar are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7.
Yes, CVE-2017-10322 is easily exploitable remotely due to its nature of allowing unauthenticated access.
Yes, CVE-2017-10322 is documented by Oracle in their security advisory for the respective affected products.