CVE-2017-10273 is a directory traversal vulnerability within the Deployment subcomponent of Oracle JDeveloper, affecting versions 11.1.1.7.0 through 12.2.1.2.0. This vulnerability has a CVSSv3 base score of 4.7 (Medium), indicating a low-impact threat. Exploitation requires a highly privileged attacker with infrastructure logon and human interaction, leading to limited unauthorized data access (read, update, insert, delete) and partial denial of service. While an ExploitDB entry exists (EDB-43848), there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1.7.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdeveloper:11.1.1.7.0:*:*:*:*:*:*:* | ||
11.1.1.7.1CPE matchmatch criteria | cpe:2.3:a:oracle:jdeveloper:11.1.1.7.1:*:*:*:*:*:*:* | ||
11.1.1.9.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdeveloper:11.1.1.9.0:*:*:*:*:*:*:* | ||
11.1.2.4.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdeveloper:11.1.2.4.0:*:*:*:*:*:*:* | ||
12.1.3.0.0CPE matchmatch criteria | cpe:2.3:a:oracle:jdeveloper:12.1.3.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.