First published: Mon Apr 24 2017(Updated: )
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Discovery Framework). Supported versions that are affected are 12.1.0, 13.1.0 and 13.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Enterprise Manager Base Platform. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Enterprise Manager | =12.1.0 | |
Oracle Enterprise Manager | =13.1.0 | |
Oracle Enterprise Manager | =13.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3518 is classified as easily exploitable and can be exploited by unauthenticated attackers with network access.
To remediate CVE-2017-3518, update Oracle Enterprise Manager Base Platform to a patched version provided by Oracle.
CVE-2017-3518 affects Oracle Enterprise Manager Base Platform versions 12.1.0, 13.1.0, and 13.2.0.
Yes, CVE-2017-3518 can be exploited remotely by unauthenticated attackers due to its network accessibility.
CVE-2017-3518 impacts the Discovery Framework of the Enterprise Manager Base Platform component in Oracle Enterprise Manager.