Learn about CVE-2017-3346 affecting Oracle Marketing in Oracle E-Business Suite versions 12.1.1 to 12.2.6. Find out the impact, technical details, and mitigation steps.
Oracle Marketing in Oracle E-Business Suite has a vulnerability that affects versions 12.1.1 to 12.2.6, allowing unauthorized access and modifications.
Understanding CVE-2017-3346
This CVE involves a weakness in the User Interface component of Oracle Marketing in Oracle E-Business Suite, impacting versions 12.1.1 to 12.2.6.
What is CVE-2017-3346?
The vulnerability in Oracle Marketing allows unauthorized individuals with network access via HTTP to compromise the system, potentially leading to unauthorized data access and modifications.
The Impact of CVE-2017-3346
Technical Details of CVE-2017-3346
This section provides more technical insights into the vulnerability.
Vulnerability Description
The vulnerability allows unauthenticated attackers to compromise Oracle Marketing through network access, impacting confidentiality and integrity with a CVSS v3.0 Base Score of 8.2.
Affected Systems and Versions
Versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6 of Oracle Marketing in Oracle E-Business Suite are affected.
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2017-3346 is crucial for maintaining security.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates