CVE-2017-10119 is an easily exploitable vulnerability in the Oracle Service Bus component of Oracle Fusion Middleware (version 11.1.1.9.0), specifically impacting the OSB Web Console Design and Admin subcomponent. A low-privileged attacker with network access via HTTP can compromise the system, requiring human interaction from a non-attacker to succeed. Successful exploitation can lead to unauthorized access to critical or all accessible data, as well as unauthorized modification of some data. This vulnerability has a CVSS 3.0 Base Score of 7.6 (High), indicating significant confidentiality and integrity impacts. The attack vector is network-based, with low attack complexity, but user interaction is required. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for the majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1.9.0CPE matchmatch criteria | cpe:2.3:a:oracle:service_bus:11.1.1.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.