PatchSiren

Oracle CVE debriefs · Page 24

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3286

CVE-2017-3286 is a medium-severity Oracle vulnerability in the Oracle Applications DBA component of Oracle E-Business Suite, specifically the Patching subcomponent. The issue was published on 2017-01-27 and affects supported versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. According to the NVD description, a high-privileged attacker with logon access to the infrastructure where Oracle Applications DBA [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3285

CVE-2017-3285 is a high-severity Oracle Service Fulfillment Manager issue in Oracle E-Business Suite, published on 2017-01-27. Oracle’s advisory and the NVD record indicate that supported versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6 are affected. The vulnerability is reachable over HTTP and can be triggered by an unauthenticated attacker, but successful attacks require human interac [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3284

CVE-2017-3284 is a high-severity Oracle E-Business Suite issue in the Service Fulfillment Manager user interface. Oracle and NVD describe it as easily exploitable over HTTP by an unauthenticated attacker, with the additional requirement that a separate person perform some human interaction. The impact is primarily confidentiality and integrity exposure, including unauthorized access to sensitive data and [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3283

CVE-2017-3283 is an Oracle Partner Management vulnerability in Oracle E-Business Suite’s user interface layer. Oracle’s NVD record describes it as network-reachable over HTTP, unauthenticated, and requiring human interaction. Successful attacks can lead to unauthorized update, insert, or delete access to some Partner Management data, with integrity impact emphasized in the CVSS v3.0 score of 4.7.

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3282

CVE-2017-3282 affects Oracle Partner Management in Oracle E-Business Suite. According to NVD and Oracle’s January 2017 CPU advisory reference, the issue is network-exploitable over HTTP, requires no attacker authentication, and does require human interaction. Successful exploitation can lead to unauthorized update, insert, or delete access to some Partner Management data, with integrity impact only in the [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3281

CVE-2017-3281 is a medium-severity Oracle Partner Management vulnerability in Oracle E-Business Suite. According to NVD, it is remotely reachable over HTTP, requires user interaction, and can allow unauthorized changes to some accessible Oracle Partner Management data. The issue affects supported versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6.

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3280

CVE-2017-3280 is a medium-severity Oracle Partner Management issue in Oracle E-Business Suite that affects supported versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. Oracle describes it as an easily exploitable vulnerability reachable over HTTP that requires human interaction and can lead to unauthorized update, insert, or delete access to some Partner Management data. NVD maps the wea [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3279

CVE-2017-3279 affects Oracle Leads Management in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3. NVD describes it as an easily exploitable issue reachable over HTTP by an unauthenticated network attacker, but successful attacks require human interaction from someone other than the attacker. The impact is primarily on confidentiality and integrity, with potential unauthorized access to critical data or [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3278

CVE-2017-3278 affects Oracle E-Business Suite’s Oracle One-to-One Fulfillment component, specifically Request Confirmation, in version 12.1.3. Oracle and NVD describe it as an easily exploitable network-accessible issue over HTTP that still requires human interaction from someone other than the attacker. The impact is primarily confidentiality and integrity, with potential unauthorized access to critical [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3277

CVE-2017-3277 is an Oracle Applications Manager (OAM Client) vulnerability in Oracle E-Business Suite that was published on 2017-01-27 and later modified in NVD on 2026-05-13. NVD and Oracle-linked references identify affected versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. The issue is rated medium severity (CVSS 4.9) and is focused on confidentiality: a high-privileged attacker with network access [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3276

CVE-2017-3276 affects Oracle Solaris 11.3 in the Kernel Zones virtualized block driver. According to NVD, exploitation is difficult and requires local access with high privileges, but successful attacks can lead to unauthorized creation, deletion, or modification of critical data, as well as repeated hangs or crashes. The CVSS v3.0 base score is 5.7 (medium), with integrity and availability impact only.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3275

CVE-2017-3275 is a high-severity Oracle Email Center issue in Oracle E-Business Suite. Oracle’s published description says an unauthenticated attacker with network access via HTTP can compromise the component, but successful exploitation requires human interaction by someone other than the attacker. Oracle also notes the impact may extend beyond Email Center itself.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3274

CVE-2017-3274 is a high-severity vulnerability in Oracle Email Center for Oracle E-Business Suite. Oracle and NVD describe it as exploitable over HTTP by an unauthenticated network attacker, but successful exploitation requires user interaction from someone other than the attacker. The issue affects supported versions 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. According to the published d [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3273

CVE-2017-3273 is a denial-of-service vulnerability in the MySQL Server component of Oracle MySQL. Oracle and NVD describe it as easily exploitable over the network by a low-privileged attacker, with impact limited to availability: affected servers can hang or crash repeatedly. The affected ranges listed by NVD are MySQL 5.6.34 and earlier, and 5.7.16 and earlier.

CRITICAL Oracle CVE published 2017-01-27

CVE-2017-3272

CVE-2017-3272 is a critical Oracle Java SE / Java SE Embedded vulnerability in the Libraries subcomponent. Oracle and NVD describe it as network-accessible, easy to exploit, and capable of full compromise in client-style Java deployments that rely on the sandbox, especially Java Web Start and applet use cases.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3271

CVE-2017-3271 is a vulnerability in Oracle Outside In Technology, a component used within Oracle Fusion Middleware. Oracle’s description says the issue is easily exploitable by an unauthenticated attacker with network access via HTTP and can lead to unauthorized access to sensitive data, unauthorized data modification, and partial denial of service. The affected versions named in the source corpus are 8.5 [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3270

CVE-2017-3270 is an Oracle Outside In Technology vulnerability that can let an unauthenticated attacker with network access via HTTP cause a hang or repeatedly crash the component, resulting in denial of service. Oracle identified affected supported versions as 8.5.2 and 8.5.3. Because Outside In Technology is an SDK used inside other software, the practical exposure depends on how the integrating applica [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3269

CVE-2017-3269 is an Oracle Outside In Technology vulnerability affecting supported versions 8.5.2 and 8.5.3. Oracle describes it as easily exploitable over the network via HTTP by an unauthenticated attacker, with successful attacks causing a hang or repeatable crash that can result in complete denial of service. The NVD record maps this to a high-severity availability issue with CVSS v3.0 7.5.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3268

CVE-2017-3268 is a high-severity availability issue in Oracle Outside In Technology. According to NVD and Oracle’s referenced CPU advisory, an unauthenticated attacker with network access via HTTP can trigger a hang or repeatable crash, resulting in complete denial of service for affected deployments. Oracle’s CVSS context also notes that impact depends on whether the embedding software forwards network-r [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3267

CVE-2017-3267 is a high-severity availability issue in Oracle Outside In Technology (Outside In Filters). According to the advisory and NVD record, an unauthenticated attacker with network access via HTTP can trigger a hang or a frequently repeatable crash, resulting in complete denial of service. The affected supported versions listed in the supplied corpus are 8.5.2 and 8.5.3.

CRITICAL Oracle CVE published 2017-01-27

CVE-2017-3266

CVE-2017-3266 is a critical Oracle Outside In Technology vulnerability affecting Outside In Filters in versions 8.5.2 and 8.5.3. NVD describes it as easily exploitable by an unauthenticated attacker with network access via HTTP, with potential takeover impact on Oracle Outside In Technology. The CVSS v3.0 base score is 9.8, but Oracle and NVD note that the real score can vary depending on how the software [truncated]

LOW Oracle CVE published 2017-01-27

CVE-2017-3264

CVE-2017-3264 is a low-severity Oracle Siebel UI Framework issue affecting Siebel CRM Open UI 16.1. NVD describes it as a network-accessible vulnerability that can let a low-privileged attacker cause unauthorized update, insert, or delete actions against some accessible data. The published CVSS v3.0 base score is 3.1, with integrity impact only.

HIGH Oracle CVE published 2017-01-27

CVE-2017-3263

CVE-2017-3263 is a high-severity Oracle Primavera P6 Enterprise Project Portfolio Management issue in the Team Member subcomponent. According to NVD, a low-privileged attacker with network access via HTTP could compromise affected systems, with the main impact being unauthorized access to and modification of Primavera P6 EPPM data. The vulnerable versions listed by NVD are 8.2, 8.3, 8.4, 15.1, 15.2, 16.1, and 16.2.

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3262

CVE-2017-3262 is a confidentiality issue in Oracle Java SE, specifically the Java Mission Control subcomponent. Oracle/NVD describe it as easily exploitable by an unauthenticated attacker with network access via multiple protocols, with successful attacks resulting in unauthorized read access to a subset of accessible data. The affected supported version identified in the record is Java SE 8u112, and the [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3261

CVE-2017-3261 is a medium-severity Oracle Java SE / Java SE Embedded vulnerability in the Networking subcomponent that can expose a subset of accessible data to an unauthenticated network attacker when a user interacts with sandboxed Java content. Oracle and NVD describe the issue as affecting Java deployments that load and run untrusted code, such as Java Web Start applications or applets, rather than tr [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3260

CVE-2017-3260 is a high-severity Oracle Java SE issue in the AWT component that affects specific Java 7u121 and 8u112 client-side deployments. Oracle says exploitation is difficult, requires network access and user interaction, and can result in takeover of Java SE. The risk is concentrated in sandboxed Java Web Start applications or applets that load untrusted code; server deployments that only run trust [truncated]

LOW Oracle CVE published 2017-01-27

CVE-2017-3259

CVE-2017-3259 is a low-severity Oracle Java SE Deployment vulnerability that affects specific JDK/JRE releases and is relevant mainly to client-side Java deployments running untrusted code in a sandbox. According to NVD, successful exploitation can allow an unauthenticated network attacker to obtain unauthorized read access to a subset of Java SE accessible data. Oracle’s affected versions listed in NVD a [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3256

CVE-2017-3256 is a network-reachable availability issue in Oracle MySQL Server’s replication component. According to NVD, a low-privileged attacker can trigger a hang or repeatedly crash the server, causing a complete denial of service. The affected product scope covers Oracle MySQL 5.7.16 and earlier.

MEDIUM Oracle CVE published 2017-01-27

CVE-2017-3255

CVE-2017-3255 is an Oracle JDeveloper vulnerability in the ADF Faces subcomponent that can be reached over HTTP by an unauthenticated attacker. NVD lists the issue as a confidentiality-only exposure with CVSS v3.0 5.8 (AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N) and identifies CWE-200. The practical risk is that exposed JDeveloper deployments may disclose a subset of accessible data without requiring login or us [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2017-3253

CVE-2017-3253 is a high-severity Oracle Java vulnerability in the 2D component that can let a network attacker cause a hang or repeatable crash, resulting in denial of service. Oracle’s CVE record and NVD list affected Java SE, Java SE Embedded, and JRockit releases, including Java SE 6u131, 7u121, 8u111/8u112, Java SE Embedded 8u111, and JRockit R28.3.12. The issue is described as exploitable through cli [truncated]