CVE-2017-10031

4 documents4 sources
Severity
7.2HIGH
EPSS
0.4%
top 39.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8
Latest updateMay 13

Description

Vulnerability in the Oracle Communications Convergence component of Oracle Communications Applications (subcomponent: Mail Proxy (dojo)). Supported versions that are affected are 3.0 and 3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergence. While the vulnerability is in Oracle Communications Convergence, attacks may significantly impact additional products. Successful attacks of this vulnerability can

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j2hx-4cm7-mxcc: Vulnerability in the Oracle Communications Convergence component of Oracle Communications Applications (subcomponent: Mail Proxy (dojo))2022-05-13
CVEList
CVE-2017-10031: Vulnerability in the Oracle Communications Convergence component of Oracle Communications Applications (subcomponent: Mail Proxy (dojo))2017-08-08

💬Community

1
Bugzilla
CVE-2017-3163 solr: Directory traversal via Index Replication HTTP API2017-05-23
CVE-2017-10031 (HIGH CVSS 7.2) | Vulnerability in the Oracle Communi | cvebase.io