CVE-2017-3553 is a critical vulnerability in the Rules Engine subcomponent of Oracle Identity Manager (version 11.1.2.3.0) within Oracle Fusion Middleware. This easily exploitable flaw allows a low-privileged attacker with network access via HTTP to compromise Oracle Identity Manager, potentially leading to a complete takeover and significant impact on additional products. With a CVSS 3.0 score of 9.9, it poses high risks to confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community discussion, indicating awareness and potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.1.2.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:identity_manager:11.1.2.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.