CERT-In Advisory
CIAD-2017-0050
Security vulnerability in Oracle Identity Manager
Original Issue Date: November 03, 2017
Severity Rating: High
Software Affected
- Oracle Identity Manager version 11.1.1.7
- Oracle Identity Manager version 11.1.1.9
- Oracle Identity Manager version 11.1.2.1.0
- Oracle Identity Manager version 11.1.2.2.0
- Oracle Identity Manager version 11.1.2.3.0
- Oracle Identity Manager version 12.2.1.3.0
Overview
A vulnerability has been reported in Oracle identity manager component of Oracle Fusion Middleware which could be exploited by a remote unauthenticated attackers to take full control over the affected systems.
Description
This vulnerability exists in Oracle Identity Manager (OIM) component of Oracle Fusion Middleware, due to "Default Account" sub component.
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to take full control over the affected systems .
Solution
Apply appropriate patches as mentioned in Oracle Security Bulletin available at
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html
Vendor Information
Oracle
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html
References
Oracle
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10151-4016513.html
Security Tracker
https://securitytracker.com/id/1039690
CVE Name
CVE-2017-10151
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|