CVE-2017-10075 is a high-severity vulnerability in Oracle WebCenter Content (versions 11.1.1.9.0, 12.2.1.1.0, and 12.2.1.2.0) that allows an unauthenticated attacker to gain unauthorized access to sensitive data and potentially modify it. The attack requires user interaction and can significantly impact other products. With a CVSS v3.0 score of 8.2, it poses a significant risk to confidentiality and integrity. While there is no evidence of active exploitation or public exploit code like Metasploit, Nuclei templates exist for Cross-Site Scripting, and its high EPSS score suggests a high likelihood of exploitation. Community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1.9.0CPE matchmatch criteria | cpe:2.3:a:oracle:webcenter_content:11.1.1.9.0:*:*:*:*:*:*:* | ||
12.2.1.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:webcenter_content:12.2.1.1.0:*:*:*:*:*:*:* | ||
12.2.1.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:webcenter_content:12.2.1.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.