These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2017-3330 affects Oracle Siebel UI Framework (Open UI) version 16.1. NVD rates it high severity with network reachability, low privileges, and required user interaction, and the listed impact is strongest on confidentiality and integrity. Oracle’s January 2017 CPU is cited as the vendor patch reference in the supplied sources.
CVE-2017-3328 is a high-severity Oracle E-Business Suite issue in the Common Applications component, specifically the Resources Module. Oracle and NVD describe it as network-reachable over HTTP, unauthenticated, and requiring human interaction. The reported impact includes unauthorized access to sensitive data and possible unauthorized modification of some accessible data. Affected versions listed by NVD [truncated]
CVE-2017-3327 is an Oracle E-Business Suite Common Applications vulnerability in the Resources Module that affects several supported 12.1.x and 12.2.x releases. Oracle and NVD describe it as network-reachable over HTTP, unauthenticated, and requiring human interaction, with potential impact to sensitive data confidentiality and integrity. Organizations running affected E-Business Suite instances should tr [truncated]
CVE-2017-3326 is a high-severity Oracle Common Applications issue in Oracle E-Business Suite’s Role Summary subcomponent. Oracle and NVD describe it as network-reachable over HTTP and unauthenticated, but exploitation requires user interaction by someone other than the attacker. Successful attacks can expose critical data and allow unauthorized changes to some accessible data.
CVE-2017-3325 is a high-severity vulnerability in Oracle Siebel CRM's Siebel UI Framework component (subcomponent: EAI) affecting version 16.1. Oracle and NVD describe it as easily exploitable by an unauthenticated attacker with network access via HTTP, but successful exploitation requires human interaction. Oracle's impact language and the NVD vector indicate confidentiality and integrity exposure, inclu [truncated]
CVE-2017-3324 is a critical Oracle Primavera P6 Enterprise Project Portfolio Management Web Access vulnerability published on 2017-01-27. Oracle/NVD identify affected versions 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, and 16.2, and the issue is reachable over HTTP by an unauthenticated attacker. Successful exploitation can affect confidentiality, integrity, and availability, including unauthorized data changes, da [truncated]
CVE-2017-3323 is a low-severity Oracle MySQL Cluster issue affecting the Cluster: General subcomponent. According to NVD, it is difficult to exploit, can be triggered by an unauthenticated network attacker via multiple protocols, and may cause a partial denial of service in MySQL Cluster.
CVE-2017-3322 is a low-severity Oracle MySQL Cluster issue in the NDBAPI subcomponent that can allow an unauthenticated network attacker to cause a partial denial of service. The NVD record lists affected Oracle MySQL Cluster versions as 7.2.25 and earlier, 7.3.14 and earlier, and 7.4.12 and earlier. The published CVSS v3.0 vector indicates network access, no user interaction, and availability-only impact.
CVE-2017-3321 is a low-severity availability issue in Oracle MySQL Cluster. According to NVD, an unauthenticated attacker with network access can trigger a partial denial of service in affected MySQL Cluster releases. The issue is described as difficult to exploit and is tied to Cluster: General, with affected versions ending at 7.2.19, 7.3.8, and 7.4.5 depending on the release line.
CVE-2017-3320 is a low-severity Oracle MySQL Server vulnerability in the Server: Security: Encryption subcomponent. Oracle and NVD describe it as affecting MySQL Server 5.7.16 and earlier, with remote network access through multiple protocols, high privileges, and human interaction required for a successful attack. The documented impact is limited to unauthorized read access to a subset of MySQL Server-ac [truncated]
CVE-2017-3319 is a low-severity information disclosure issue in Oracle MySQL Server’s X Plugin component. Oracle’s description says a low-privileged attacker with network access could compromise affected MySQL Server deployments and obtain unauthorized read access to a subset of MySQL Server accessible data. The affected range in the record is MySQL 5.7.16 and earlier.
CVE-2017-3316 is a high-severity Oracle VM VirtualBox GUI vulnerability affecting VirtualBox versions prior to 5.0.32 and prior to 5.1.14. Oracle’s description says exploitation is easily achievable by a high-privileged attacker with network access via multiple protocols, but successful attacks require human interaction by another person. If exploited, the issue can lead to takeover of Oracle VM VirtualBo [truncated]
CVE-2017-3315 is a confidentiality issue in Oracle PeopleSoft Enterprise HCM ePerformance (Security subcomponent) affecting version 9.2. According to the CVE record, a low-privileged attacker with network access over HTTP could read a subset of accessible ePerformance data. The issue is rated CVSS 3.0 4.3 (Medium) and maps to CWE-200, information exposure.
CVE-2017-3314 is a medium-severity Oracle FLEXCUBE Universal Banking issue affecting supported versions 12.0.0, 12.1.0, and 12.2.0. Oracle and NVD describe it as remotely reachable over HTTP by an unauthenticated attacker, but with a user interaction requirement. Successful exploitation can lead to unauthorized read access and unauthorized update/insert/delete access to some accessible data, which makes i [truncated]
CVE-2017-3311 is an Oracle Application Testing Suite vulnerability affecting the Test Manager for Web Apps subcomponent in Oracle Enterprise Manager Grid Control. According to the CVE/NVD record, it was publicly disclosed on 2017-01-27 and is rated medium severity (CVSS 5.3). The issue is network-reachable over HTTP, requires no authentication, and can lead to unauthorized update, insert, or delete access [truncated]
CVE-2017-3310 is a critical vulnerability in the Oracle Database Server OJVM component. Oracle and NVD describe it as easily exploitable by a low-privileged attacker with Create Session and Create Procedure privileges, reachable over the network via multiple protocols. Successful attacks require human interaction from someone other than the attacker and can result in takeover of OJVM, with potential impac [truncated]
CVE-2017-3303 affects the Oracle XML Gateway component of Oracle E-Business Suite, specifically the Oracle Transport Agent subcomponent. According to NVD, the issue is exploitable over the network via HTTP, requires user interaction, and can lead to unauthorized access to sensitive XML Gateway data as well as unauthorized data modification. Oracle lists affected supported versions as 12.1.1, 12.1.2, 12.1. [truncated]
CVE-2017-3301 is a low-severity Oracle Solaris kernel vulnerability affecting Solaris 11.3 as identified in NVD data. The published description says an attacker with logon access to the infrastructure where Solaris executes can potentially cause unauthorized update, insert, or delete actions against some Solaris-accessible data, but successful exploitation requires human interaction from another person. T [truncated]
CVE-2017-3300 is a medium-severity Oracle PeopleSoft Enterprise PeopleTools issue affecting the Multichannel Framework in supported versions 8.54 and 8.55. The NVD record describes it as an unauthenticated, network-accessible flaw over HTTP that requires human interaction from another user. Successful exploitation can lead to unauthorized data read and modification within PeopleTools-accessible data, with [truncated]
CVE-2017-3299 is an Oracle PeopleSoft Enterprise PeopleTools vulnerability in the PIA Search Functionality affecting supported versions 8.54 and 8.55. Oracle/NVD describe it as easily exploitable over HTTP by an unauthenticated network attacker, but successful exploitation requires human interaction from someone other than the attacker. If exploited, the issue can expose a subset of PeopleSoft PeopleTools [truncated]
CVE-2017-3298 affects Oracle PeopleSoft Enterprise PeopleTools, specifically the PIA Core Technology subcomponent, in supported versions 8.54 and 8.55. According to the NVD record, an attacker with network access over HTTP can exploit the issue without authentication, but successful exploitation requires interaction from another person. The impact includes unauthorized read access to some accessible Peopl [truncated]
CVE-2017-3297 is a medium-severity Oracle FLEXCUBE Direct Banking vulnerability affecting the Framework subcomponent in supported versions 12.0.2 and 12.0.3. According to Oracle and NVD, a low-privileged attacker with network access via HTTP may be able to compromise the application and gain unauthorized access to critical data or all accessible data. NVD rates the issue CVSS 3.0 5.3 with confidentiality [truncated]
CVE-2017-3296 is a medium-severity Oracle Commerce Platform issue in the Dynamo Application Framework component. NVD describes it as an easily exploitable vulnerability reachable over HTTP by an unauthenticated attacker, but successful exploitation requires user interaction from someone other than the attacker. The documented impact is limited to unauthorized read access to a subset of Oracle Commerce Pla [truncated]
CVE-2017-3295 is an Oracle Outside In Technology vulnerability that can let an unauthenticated attacker over the network trigger a hang or repeatable crash, resulting in complete denial of service. Oracle identifies affected supported versions as 8.5.2 and 8.5.3. The issue is availability-only, with the practical risk depending on whether a product passes network-received data directly into Outside In Technology.
CVE-2017-3294 is a high-severity denial-of-service issue in Oracle Outside In Technology, specifically the Outside In Filters subcomponent used by Oracle Fusion Middleware. According to the source record, an unauthenticated attacker with network access via HTTP can trigger a hang or a frequently repeatable crash in affected versions 8.5.2 and 8.5.3. The published CVSS v3.0 score is 7.5, driven by availabi [truncated]
CVE-2017-3293 is an Oracle Outside In Technology vulnerability affecting supported versions 8.5.2 and 8.5.3 in Oracle Fusion Middleware. Oracle’s description says the issue is easily exploitable by an unauthenticated attacker with network access via HTTP, and successful attacks can lead to unauthorized access to critical data, unauthorized data modification, and partial denial of service. The source also [truncated]
CVE-2017-3292 affects Oracle PeopleSoft Enterprise PeopleTools, specifically the Integration Broker subcomponent, in supported versions 8.54 and 8.55. The NVD record describes a network-reachable issue that is easily exploitable by a low-privileged attacker over HTTP, but it also requires human interaction from someone other than the attacker. The main impact is confidentiality: successful exploitation ca [truncated]
CVE-2017-3290 is a high-severity Oracle VM VirtualBox vulnerability in the Shared Folder component. According to the NVD record, affected releases include VirtualBox prior to 5.0.32 and prior to 5.1.14. The issue requires a local attacker with high privileges and logon access on the system where VirtualBox runs, but successful exploitation can affect integrity and availability of VirtualBox data and servi [truncated]
CVE-2017-3289 is a critical Oracle Java SE / Java SE Embedded vulnerability in Hotspot that affects specific Java 7 and 8 update levels. The supplied description says it is easily exploitable over the network, requires user interaction, and can lead to takeover of affected Java deployments that load untrusted code in sandboxed Java Web Start applications or applets. Oracle’s own January 2017 CPU is listed [truncated]
CVE-2017-3287 affects Oracle iStore in Oracle E-Business Suite and is rated CVSS 8.2 (HIGH). Oracle’s published description says an unauthenticated attacker with network access via HTTP can compromise Oracle iStore, but successful attacks require human interaction by someone other than the attacker. The issue can lead to unauthorized access to critical data or complete access to all Oracle iStore-accessib [truncated]