CVE-2017-3549

CRITICAL

Oracle E-Business Suite <12.2.6 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-3549. PoCs published by ERPScan.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Oracle E-Business Suite 12.2.3 via the `iesfootprint.jsp` endpoint. The PoC shows how an attacker can manipulate the `dscriptId`, `deployDate`, and `responseDate` parameters to inject arbitrary SQL queries, potentially leading to unauthorized data access or modification.

Description

Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.0 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Exploits (1)

exploitdb WORKING POC
by ERPScan · textwebappsjsp
https://www.exploit-db.com/exploits/41926

This exploit demonstrates an SQL injection vulnerability in Oracle E-Business Suite 12.2.3 via the `iesfootprint.jsp` endpoint. The PoC shows how an attacker can manipulate the `dscriptId`, `deployDate`, and `responseDate` parameters to inject arbitrary SQL queries, potentially leading to unauthorized data access or modification.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Oracle E-Business Suite 12.2.3
No auth needed
Prerequisites: Network access to the vulnerable Oracle EBS instance · The vulnerable `iesfootprint.jsp` endpoint must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97748
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038299
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/41926/

Scores

CVSS v3 9.1
EPSS 0.1578
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (14)
oracle/scripting 12.1.1
oracle/scripting 12.1.2
oracle/scripting 12.1.3
oracle/scripting 12.2.3
oracle/scripting 12.2.4
oracle/scripting 12.2.5
oracle/scripting 12.2.6
Oracle Corporation/Scripting 12.1.1
Oracle Corporation/Scripting 12.1.2
Oracle Corporation/Scripting 12.1.3
... and 4 more
Published Apr 24, 2017
Tracked Since Feb 18, 2026