These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2017-3367 is a high-severity Oracle Knowledge Management vulnerability in Oracle E-Business Suite. Oracle and NVD describe it as an easily exploitable issue reachable over HTTP by an unauthenticated attacker, but with a user interaction requirement. The expected impact is serious: unauthorized access to critical data, full access to Oracle Knowledge Management data, and unauthorized modification of so [truncated]
CVE-2017-3366 is a high-severity Oracle Knowledge Management vulnerability in Oracle E-Business Suite. According to NVD and the Oracle-linked advisory reference, affected supported versions include 12.1.1, 12.1.2, and 12.1.3. The issue is network-reachable over HTTP and does not require authentication, but successful exploitation does require human interaction by a person other than the attacker. Impact i [truncated]
CVE-2017-3365 is a high-severity Oracle Knowledge Management vulnerability in Oracle E-Business Suite’s User Interface component. NVD lists affected supported versions as 12.1.1, 12.1.2, and 12.1.3. The issue is network-reachable over HTTP and does not require authentication, but successful exploitation does require human interaction from someone other than the attacker. Oracle and NVD describe potential [truncated]
CVE-2017-3364 is a high-severity Oracle Knowledge Management vulnerability in Oracle E-Business Suite. Oracle and NVD identify affected supported versions as 12.1.1, 12.1.2, and 12.1.3. The issue is network-reachable over HTTP, requires no attacker authentication, and can still have serious consequences because successful exploitation may expose critical data or allow unauthorized updates, inserts, or del [truncated]
CVE-2017-3363 is a high-severity vulnerability in the Oracle Knowledge Management component of Oracle E-Business Suite, specifically the User Interface subcomponent. Oracle identifies supported affected versions as 12.1.1, 12.1.2, and 12.1.3. The issue is network-reachable over HTTP and is described as easily exploitable by an unauthenticated attacker, but successful exploitation requires human interactio [truncated]
CVE-2017-3362 is a high-severity Oracle Knowledge Management vulnerability in Oracle E-Business Suite's User Interface subcomponent. According to the CVE record, it is easily exploitable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction from someone other than the attacker. The reported impact is primarily on confidentiality and integrity, including unauthori [truncated]
CVE-2017-3361 affects the Oracle Installed Base user interface in Oracle E-Business Suite. Oracle and NVD describe it as network-reachable over HTTP, unauthenticated, but requiring interaction from another person. Successful exploitation can expose critical data and permit unauthorized modification of some Installed Base data.
CVE-2017-3360 is a high-severity Oracle Customer Intelligence vulnerability in Oracle E-Business Suite. According to NVD, it affects supported versions 12.1.1, 12.1.2, and 12.1.3 and is accessible over HTTP from a network attacker without authentication, but successful exploitation requires human interaction. The published impact is serious: unauthorized access to critical data, full access to Oracle Cust [truncated]
CVE-2017-3359 is an Oracle Customer Intelligence vulnerability in Oracle E-Business Suite affecting supported versions 12.1.1, 12.1.2, and 12.1.3. Oracle and NVD describe it as network-accessible over HTTP and easily exploitable, but with successful attacks requiring human interaction. Impact can include unauthorized access to critical data and unauthorized update, insert, or delete access to some Custome [truncated]
CVE-2017-3358 is a high-severity vulnerability in the Oracle Marketing component of Oracle E-Business Suite, specifically the User Interface subcomponent. Oracle and NVD describe it as easily exploitable over the network via HTTP by an unauthenticated attacker, with the important caveat that successful exploitation requires human interaction from someone other than the attacker. If successful, the impact [truncated]
CVE-2017-3357 is a high-severity Oracle Marketing issue in Oracle E-Business Suite. Oracle and NVD describe it as remotely reachable over HTTP, requiring human interaction from someone other than the attacker, and capable of exposing critical data or allowing unauthorized changes in Oracle Marketing data. The affected supported versions include 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.
CVE-2017-3354 is a high-severity vulnerability in the Oracle Marketing component of Oracle E-Business Suite. Oracle and NVD describe it as easily exploitable by an unauthenticated attacker with network access via HTTP, but successful exploitation requires human interaction. If exploited, it can expose critical Oracle Marketing data and allow unauthorized changes to some Oracle Marketing data.
CVE-2017-3353 affects the Oracle Marketing component of Oracle E-Business Suite, specifically the User Interface subcomponent. Oracle describes it as easily exploitable over HTTP by an unauthenticated network attacker, but successful exploitation requires human interaction from another person. The impact is serious: attackers may gain unauthorized access to critical data or all Oracle Marketing accessible [truncated]
CVE-2017-3352 is a high-severity Oracle Marketing vulnerability in Oracle E-Business Suite. Oracle and NVD describe it as an easily exploitable issue that can be reached over HTTP by an unauthenticated attacker, but it requires human interaction. If exploited, it can expose critical data and allow unauthorized changes to Oracle Marketing data, with possible impact beyond the Marketing component. The CVE w [truncated]
CVE-2017-3351 is a high-severity vulnerability in Oracle Marketing, a component of Oracle E-Business Suite. The issue is remotely reachable over HTTP, does not require attacker authentication, and can affect confidentiality and integrity of Oracle Marketing data. Because successful exploitation requires human interaction, defenders should treat it as a serious but user-assisted web exposure risk. The CVE [truncated]
CVE-2017-3350 is a high-severity Oracle Marketing vulnerability in Oracle E-Business Suite that can be reached over HTTP by an unauthenticated network attacker, but successful exploitation requires human interaction from someone other than the attacker. Oracle and NVD describe potentially serious confidentiality and integrity impact, including unauthorized access to critical data and unauthorized update/i [truncated]
CVE-2017-3349 affects the Oracle Marketing component of Oracle E-Business Suite. Oracle describes it as an easily exploitable issue reachable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction from someone other than the attacker. The impact can include unauthorized access to critical data and unauthorized update, insert, or delete access to some Oracle Marketing data.
CVE-2017-3348 is a high-severity Oracle Marketing vulnerability in Oracle E-Business Suite's User Interface component. Oracle and NVD describe it as easily exploitable over HTTP by an unauthenticated network attacker, but with required human interaction. Successful exploitation can expose critical data and allow unauthorized changes in Oracle Marketing, with possible impact beyond the component itself. Th [truncated]
CVE-2017-3346 is a high-severity Oracle Marketing vulnerability in the Oracle E-Business Suite user interface. Oracle and NVD describe it as easily exploitable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction from someone other than the attacker. The issue can expose critical data and may allow unauthorized read and write access to Oracle Marketing data. Ora [truncated]
CVE-2017-3344 affects the Oracle Marketing component of Oracle E-Business Suite, specifically the User Interface subcomponent. Oracle and NVD describe it as an easily exploitable vulnerability over HTTP that does not require authentication but does require human interaction from someone other than the attacker. Successful exploitation can lead to unauthorized access to critical data, complete access to Or [truncated]
CVE-2017-3343 is a high-severity vulnerability in the Oracle Marketing component of Oracle E-Business Suite, specifically the User Interface subcomponent. Oracle’s description indicates the issue is easily exploitable by an unauthenticated attacker with network access via HTTP, but successful exploitation requires human interaction from someone other than the attacker. The main risk is loss of confidentia [truncated]
CVE-2017-3341 is a high-severity Oracle Marketing vulnerability in Oracle E-Business Suite’s user interface component. According to the NVD record, an unauthenticated attacker with network access via HTTP can exploit the issue, but successful attacks require human interaction from someone other than the attacker. Oracle’s description indicates the impact can include unauthorized access to critical data, c [truncated]
CVE-2017-3340 is an Oracle Marketing vulnerability in Oracle E-Business Suite’s user interface component. Oracle’s description says it is easily exploitable over HTTP by an unauthenticated network attacker, but successful exploitation requires human interaction from someone other than the attacker. The stated impact is serious confidentiality and integrity exposure, including unauthorized access to critic [truncated]
CVE-2017-3339 affects the Oracle Marketing component of Oracle E-Business Suite, specifically the User Interface subcomponent. According to the NVD record, an unauthenticated attacker with network access via HTTP can exploit the issue, but success requires human interaction by a person other than the attacker. Oracle’s advisory and the NVD entry identify affected supported versions including 12.1.1, 12.1. [truncated]
CVE-2017-3338 affects the Oracle Marketing component of Oracle E-Business Suite. Oracle and NVD describe it as an easily exploitable issue reachable over HTTP by an unauthenticated attacker, but successful exploitation requires human interaction from a separate person. The issue can expose critical Oracle Marketing data and allow unauthorized modification of some data, giving it a CVSS v3.0 base score of 8.2 (High).
CVE-2017-3336 affects Oracle Marketing in Oracle E-Business Suite and was published on 2017-01-27; NVD last modified the record on 2026-05-13. The issue is network-reachable over HTTP, does not require authentication, and needs human interaction from someone other than the attacker. Oracle’s advisory and NVD record indicate impacts to confidentiality and integrity, including unauthorized access to critica [truncated]
CVE-2017-3335 is a high-severity vulnerability in the Oracle Marketing component of Oracle E-Business Suite. According to the NVD record, an unauthenticated attacker with network access via HTTP can compromise Oracle Marketing, but success requires user interaction. Oracle’s description says the issue can lead to unauthorized access to critical data or complete access to Oracle Marketing accessible data, [truncated]
CVE-2017-3334 is a high-severity Oracle Marketing vulnerability in Oracle E-Business Suite that can be reached over HTTP by an unauthenticated network attacker, but successful exploitation requires user interaction. Oracle’s affected supported versions include 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The issue can lead to unauthorized access to critical data and unauthorized update, ins [truncated]
CVE-2017-3333 is a high-severity Oracle Marketing vulnerability in Oracle E-Business Suite that Oracle and NVD describe as easily exploitable over HTTP by an unauthenticated attacker, but with required human interaction. The impact is primarily confidentiality and integrity loss, with potential unauthorized access to critical data and write actions against some Oracle Marketing data.
CVE-2017-3332 is a high-severity Oracle VM VirtualBox vulnerability in the SVGA Emulation component. According to the supplied Oracle/NVD record, a low-privileged attacker with logon access to the system running VirtualBox could compromise the application, leading to unauthorized data modification and repeated crashes or denial of service. The record also notes that impact may extend beyond VirtualBox itself.