CVE-2017-3619

MEDIUM

Oracle Support Tools <5.7 - Privilege Escalation

Title source: llm

Description

Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes to compromise Automatic Service Request (ASR). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Automatic Service Request (ASR) accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

Scores

CVSS v3 5.5
EPSS 0.0011
EPSS Percentile 29.3%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

Status published

Affected Products (2)

oracle/automatic_service_request < 5.5.1
Oracle Corporation/Automatic Service Request (ASR) < 5.7

Timeline

Published Apr 24, 2017
Tracked Since Feb 18, 2026