CVE-2017-10151 is a critical vulnerability in Oracle Identity Manager (versions 11.1.1.7, 11.1.2.3, and 12.2.1.3), specifically within its "Default Account" subcomponent. This easily exploitable flaw allows an unauthenticated attacker to remotely compromise Oracle Identity Manager via HTTP, potentially leading to a complete takeover and significant impact on other integrated products. With a CVSS v3.0 score of 10.0, it poses severe confidentiality, integrity, and availability risks. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered notable community discussion and media coverage, indicating awareness despite no active exploitation listed in KEV.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1.7CPE matchmatch criteria | cpe:2.3:a:oracle:identity_manager:11.1.1.7:*:*:*:*:*:*:* | ||
11.1.1.9CPE matchmatch criteria | cpe:2.3:a:oracle:identity_manager:11.1.1.9:*:*:*:*:*:*:* | ||
11.1.2.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:identity_manager:11.1.2.1.0:*:*:*:*:*:*:* | ||
11.1.2.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:identity_manager:11.1.2.2.0:*:*:*:*:*:*:* | ||
11.1.2.3CPE matchmatch criteria | cpe:2.3:a:oracle:identity_manager:11.1.2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.