CVE-2017-3518: High severity Oracle Enterprise Manager Base Platform vulnerability
Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Discovery Framework). Supported versions that are affected are 12.1.0, 13.1.0 and 13.2.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Enterprise Manager Base Platform. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3518?
CVE-2017-3518 is classified as easily exploitable and can be exploited by unauthenticated attackers with network access.
How do I fix CVE-2017-3518?
To remediate CVE-2017-3518, update Oracle Enterprise Manager Base Platform to a patched version provided by Oracle.
Which versions are affected by CVE-2017-3518?
CVE-2017-3518 affects Oracle Enterprise Manager Base Platform versions 12.1.0, 13.1.0, and 13.2.0.
Can CVE-2017-3518 be exploited remotely?
Yes, CVE-2017-3518 can be exploited remotely by unauthenticated attackers due to its network accessibility.
What component is impacted by CVE-2017-3518?
CVE-2017-3518 impacts the Discovery Framework of the Enterprise Manager Base Platform component in Oracle Enterprise Manager.