CVE-2017-3487
published 2017-04-24CVE-2017-3487: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust). Supported versions that…
PriorityP412low3.1CVSS 3.0
AVNACHPRLUINSUCNILAN
EPSS
0.97%
57.6th percentile
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm3 | 2.26.1-1ubuntu1~16.04.8+esm3 |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle | flexcube_investor_servicing | — | — |
| oracle_corporation | flexcube_investor_servicing | — | — |
| oracle_corporation | flexcube_investor_servicing | — | — |
| oracle_corporation | flexcube_investor_servicing | — | — |
| oracle_corporation | flexcube_investor_servicing | — | — |
| oracle_corporation | flexcube_investor_servicing | — | — |
| oracle_corporation | flexcube_investor_servicing | — | — |
| oracle_corporation | flexcube_investor_servicing | — | — |
CVSS provenance
nvdv3.03.1LOWCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv7.8HIGH
vendor_apache9.8
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mm6f-q9qp-cq3w: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust)
ghsa_unreviewed·2022-05-13
CVE-2017-3487 [LOW] GHSA-mm6f-q9qp-cq3w: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust)
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).
OSV
binutils vulnerabilities
osv·2022-03-22·CVSS 7.8
CVE-2017-17122 binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled checks for memory
allocation when parsing relocs in a corrupt file. An attacker could possibly
use this issue to cause a denial of service. (CVE-2017-17122)
It was discovered that GNU binutils incorrectly handled certain corrupt DWARF
debug sections. An attacker could possibly use this issue to cause GNU
binutils to consume memory, resulting in a denial of service. (CVE-2021-3487)
It was discovered that GNU binutils incorrectly performed bounds checking
operations when parsing stabs debugging information. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2021-45078)
Apache
Apache nifi: CVE-2017-5635
vendor_apache·CVSS 7.5
CVE-2017-5635 Apache nifi: CVE-2017-5635
Apache nifi: CVE-2017-5635
Title: Improper Authentication of Replicated Cluster HTTP Requests Published: 2017-02-20 Severity: Medium Products: Apache NiFi Affected Versions: 0.7.0 to 0.7.1 and 1.1.0 to 1.1.1 Fixed Versions: 0.7.2 and 1.1.2 Reporter: Leonardo Dias and Matt Gilman References CVE Record: CVE-2017-5635 NVD Record: CVE-2017-5635 Apache Jira Issue: NIFI-3487 In a cluster environment, if an anonymous user request is replicated to another node, the originating node identity is used rather than the anonymous user. NiFi 0.7.2 and 1.1.2 remove the negative check for anonymous user before building the proxy chain and throwing an exception, and evaluating each user in the proxy chain iteration and comparing against a static constant anonymous user. Users running a prior release should
Apache
Apache nifi: CVE-2017-5636
vendor_apache·CVSS 9.8
CVE-2017-5636 Apache nifi: CVE-2017-5636
Apache nifi: CVE-2017-5636
Title: Improper Authentication of Replicated Cluster HTTP Requests Published: 2017-02-20 Severity: Medium Products: Apache NiFi Affected Versions: 0.7.0 to 0.7.1 and 1.1.0 to 1.1.1 Fixed Versions: 0.7.2 and 1.1.2 Reporter: Andy LoPresto References CVE Record: CVE-2017-5636 NVD Record: CVE-2017-5636 Apache Jira Issue: NIFI-3487 In a cluster environment, the proxy chain serialization and deserialization is vulnerable to an injection attack where a carefully crafted username could impersonate another user and gain their permissions on a replicated request to another node. NiFi 0.7.2 and 1.1.2 modify the tokenization code and sanitization of user-provided input. Users running a prior release should upgrade to 0.7.2 or 1.1.2.
Severity: moderate
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97871http://www.securitytracker.com/id/1038304http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97871http://www.securitytracker.com/id/1038304
2017-04-24
Published