CVE-2017-10151
published 2017-10-30CVE-2017-10151: Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are…
PriorityP264critical10CVSS 3.0
AVNACLPRNUINSCCHIHAH
EPSS
3.95%
89.2th percentile
Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | identity_manager | — | — |
| oracle | identity_manager | — | — |
| oracle | identity_manager | — | — |
| oracle | identity_manager | — | — |
| oracle | identity_manager | — | — |
| oracle | identity_manager | — | — |
| oracle_corporation | identity_manager | — | — |
| oracle_corporation | identity_manager | — | — |
| oracle_corporation | identity_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http any any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Possible Oracle Identity Manager Attempt to Logon with default account"; flow:established,to_server; http.request_body; content:"=OIMINTERNAL"; fast_pattern; reference:cve,CVE-2017-10151; reference:url,oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html; classtype:attempted-admin; sid:2024941; rev:5; metadata:affected_product Oracle_Identity_Manager, attack_target Web_Server, created_at 2017_11_01, deployment Datacenter, performance_impact Low, confidence Medium, signature_severity Critical, updated_at 2024_03_07;)
bytes
=OIMINTERNAL
- →Exploit attempts use HTTP POST requests to Oracle Identity Manager with the string '=OIMINTERNAL' present in the HTTP request body, indicating use of the default internal account credential.
- →Traffic should be inspected on inbound HTTP to web servers; the attack requires no authentication and no user interaction, originating from any network source.
- →Successful exploitation results in full takeover of Oracle Identity Manager and may significantly impact additional (downstream) products — treat any match as critical severity.
- ·The Snort/ET rule (sid:2024941) targets the HTTP request body for '=OIMINTERNAL'; ensure your IDS/IPS is configured for deep HTTP inspection (request body visibility) on traffic destined to Oracle Identity Manager web servers, otherwise the signature will not fire.
- ·The vulnerability is scoped as 'Changed' (S:C) in CVSS, meaning lateral impact to other products beyond Oracle Identity Manager is expected — detection and containment scope should extend beyond the OIM host itself.
CVSS provenance
nvdv3.010.0CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT Possible Oracle Identity Manager Attempt to Logon with default account
suricata·2017-11-01·CVSS 10.0
CVE-2017-10151 [CRITICAL] ET EXPLOIT Possible Oracle Identity Manager Attempt to Logon with default account
ET EXPLOIT Possible Oracle Identity Manager Attempt to Logon with default account
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Possible Oracle Identity Manager Attempt to Logon with default account"; flow:established,to_server; http.request_body; content:"=OIMINTERNAL"; fast_pattern; reference:cve,CVE-2017-10151; reference:url,oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html; classtype:attempted-admin; sid:2024941; rev:5; metadata:affected_product Oracle_Identity_Manager, attack_target Web_Server, created_at 2017_11_01, deployment Datacenter, performance_impact Low, confidence Medium, signature_severity Critical, updated_at 2024_03_07;)
No public exploits indexed.
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.htmlhttp://www.securityfocus.com/bid/101619http://www.securitytracker.com/id/1039690http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.htmlhttp://www.securityfocus.com/bid/101619http://www.securitytracker.com/id/1039690
2017-10-30
Published