CVE-2017-10272 is a critical vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware, specifically affecting versions 11.1.1, 12.1.1, 12.1.3, and 12.2.2. This easily exploitable flaw allows a low-privileged attacker with network access via Jolt to compromise Oracle Tuxedo. With a CVSS 3.0 Base Score of 9.9, successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, complete data access, and partial denial of service. While not listed in CISA KEV, the vulnerability has garnered significant community attention with two media articles and two community mentions, indicating awareness and concern. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and its EPSS score is low, suggesting a lower probability of active exploitation despite its high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:11.1.1:*:*:*:*:*:*:* | ||
12.1.1CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.1.1:*:*:*:*:*:*:* | ||
12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.1.3:*:*:*:*:*:*:* | ||
12.2.2CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.