PT-2017-11346 · Oracle · Oracle Virtual Directory

Published

2017-10-19

·

Updated

2019-10-03

·

CVE-2017-10369

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Virtual Directory versions 11.1.1.7.0 and 11.1.1.9.0
Description The issue allows a low-privileged attacker with network access via HTTP to compromise Oracle Virtual Directory, potentially resulting in a takeover. The attack is considered difficult to exploit.
Recommendations For version 11.1.1.7.0, update to a version that includes the fix for this issue. For version 11.1.1.9.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Oracle Virtual Directory Server to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-10369

Affected Products

Oracle Virtual Directory