CVE-2017-10331: Infoleak
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10331?
CVE-2017-10331 is classified as a high severity vulnerability that allows unauthenticated attackers to exploit the Oracle Application Object Library.
How do I fix CVE-2017-10331?
To fix CVE-2017-10331, you should apply the latest patch provided by Oracle for affected versions of the Oracle Application Object Library.
Which versions are affected by CVE-2017-10331?
CVE-2017-10331 affects Oracle Application Object Library versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, and 12.2.7.
Can CVE-2017-10331 be exploited remotely?
Yes, CVE-2017-10331 can be easily exploited by an unauthenticated attacker with network access.
Is there a workaround for CVE-2017-10331?
No specific workarounds are recommended for CVE-2017-10331; the best course of action is to apply the necessary security updates.