CVE-2010-2370 is an unspecified integrity vulnerability within the Oracle Business Process Management (BPM) component of Oracle Fusion Middleware versions 5.7 MP3, 6.0 MP5, and 10.3 MP2. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and requiring no authentication, allowing remote attackers to impact data integrity without affecting confidentiality or availability. While not actively exploited in the wild (KEV), an ExploitDB entry exists for a cross-site scripting (XSS) vulnerability in version 10.3.2, which aligns with the integrity impact. Despite its age, it has a FAUCET Risk Score of 87/100, though it lacks significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.7CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:5.7:mp3:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:6.0:mp5:*:*:*:*:*:* | ||
10.3CPE matchmatch criteria | cpe:2.3:a:oracle:fusion_middleware:10.3:mp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.