CVE-2017-10091Corporation Enterprise Manager Base Platform vulnerability

3 documents3 sources
Severity
7.7HIGHNVD
EPSS
0.5%
top 34.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8
Latest updateMay 13

Description

Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework). Supported versions that are affected are 12.1.0, 13.1.0 and 13.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. While the vulnerability is in Enterprise Manager Base Platform, attacks may significantly impact additional products. Successful attacks of this vulnerabil

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:NExploitability: 3.1 | Impact: 4.0

Affected Packages2 packages

NVDoracle/enterprise_manager_base_platform12.1.0, 13.1.0, 13.2.0+2
CVEListV5oracle_corporation/enterprise_manager_base_platform12.1.0, 13.1.0, 13.2.0+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4jx9-m4fq-r8v8: Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework)2022-05-13
CVEList
CVE-2017-10091: Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: UI Framework)2017-08-08
CVE-2017-10091 — HIGH severity | cvebase