PT-2017-15987 · Oracle · Oracle Identity Manager
Published
2017-04-24
·
Updated
2019-10-03
·
CVE-2017-3553
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Oracle Identity Manager version 11.1.2.3.0
Description
The issue affects the Rules Engine subcomponent of Oracle Identity Manager, allowing a low-privileged attacker with network access via HTTP to compromise Oracle Identity Manager. This can result in the takeover of Oracle Identity Manager and may have significant impacts on additional products.
Recommendations
For Oracle Identity Manager version 11.1.2.3.0, update to a version that includes a fix for this issue to prevent potential exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Identity Manager