CVE-2017-10278 is a vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware, specifically affecting versions 11.1.1, 12.1.1, 12.1.3, and 12.2.2. This vulnerability, with a CVSS 3.0 Base Score of 7.0 (High), allows an unauthenticated attacker with network access via Jolt to compromise the system. While difficult to exploit, successful attacks can lead to unauthorized access to critical or all accessible data, unauthorized data modification, and partial denial of service. There is no evidence of active exploitation, and public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.1CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:11.1.1:*:*:*:*:*:*:* | ||
12.1.1CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.1.1:*:*:*:*:*:*:* | ||
12.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.1.3:*:*:*:*:*:*:* | ||
12.2.2CPE matchmatch criteria | cpe:2.3:a:oracle:tuxedo:12.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.