CVE-2017-10266 is an easily exploitable vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware, specifically affecting versions 11.1.1, 12.1.1, 12.1.3, and 12.2.2. This vulnerability allows an unauthenticated attacker with network access via Jolt to gain unauthorized read access to a subset of Oracle Tuxedo accessible data. With a CVSS 3.0 Base Score of 5.3 (Medium), it presents a low-complexity attack vector requiring no user interaction. While not listed in CISA's KEV catalog, there is no public exploit code available, and community discussion and media coverage indicate some awareness but no widespread active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:11.1.1:*:*:*:*:*:*:* | ||
12.1.1CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.1.1:*:*:*:*:*:*:* | ||
12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.1.3:*:*:*:*:*:*:* | ||
12.2.2CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.