Record summary

CVE-2017-10246 has a selected CVSS score of 8.2 (high); EIP currently links 1 catalogued exploit.

Description

Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: iHelp). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 4, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List12.1.3affected
12.2.3affected
12.2.4affected
12.2.5affected
12.2.6affected

Proofs of concept

1

Catalogued exploits

ExploitDBOracle E-Business Suite 12.x - Server-Side Request ForgeryExploitDB exploitby Sarath NairNot analyzed1 file
ExploitDB

PoC details

References

5