Learn about CVE-2017-3356 affecting Oracle Marketing in E-Business Suite versions 12.1.1 to 12.2.6. Unauthenticated attackers can exploit this vulnerability via HTTP, potentially compromising critical data.
Oracle Marketing component of Oracle E-Business Suite has a vulnerability in the User Interface subcomponent, affecting versions 12.1.1 to 12.2.6. An unauthenticated attacker with network access via HTTP can exploit this vulnerability, potentially compromising Oracle Marketing.
Understanding CVE-2017-3356
This CVE involves a critical vulnerability in the Oracle Marketing component of Oracle E-Business Suite, impacting various versions.
What is CVE-2017-3356?
The vulnerability lies in the User Interface subcomponent of Oracle Marketing in E-Business Suite.
Affected versions include 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.
Exploitation can lead to unauthorized access and manipulation of critical Oracle Marketing data.
The Impact of CVE-2017-3356
Successful exploitation can grant unauthorized individuals creation, deletion, or modification access to critical or all Oracle Marketing data.
Unauthorized read access to a portion of Oracle Marketing data is also possible.
The CVSS 3.0 base score for this vulnerability is 7.1, with impacts on confidentiality and integrity.
Technical Details of CVE-2017-3356
This section provides detailed technical information about the vulnerability.
Vulnerability Description
Vulnerability in the User Interface subcomponent of Oracle Marketing in E-Business Suite.
Exploitable by an unauthenticated attacker with network access via HTTP.