CERT-In Advisory
CIAD-2017-0051
Security vulnerability in Oracle Fusion Middleware
Original Issue Date: November 21, 2017
Severity Rating: High
Software Affected
- Oracle Tuxedo version 11.1.1
- Oracle Tuxedo version 12.1.1
- Oracle Tuxedo version 12.1.3
- Oracle Tuxedo version 12.2.2
Overview
Multiple vulnerabilities have been reported in Oracle Tuxedo component of Oracle Fusion Middleware which could be exploited by an unauthenticated or low privileged attackers to take complete access over the affected systems.
Description
Multiple vulnerabilities exist in Oracle Tuxedo component of Oracle Fusion Middleware, due to "Core and Security " sub component. An Unauthenticated or low privileged attacker could exploit these vulnerabilities via "Jolt" protocol.
Successful exploitation of these vulnerabilities could allow an unauthenticated or low privileged attacker to take complete access over the affected systems and cause partial denial of service condition.
Solution
Apply appropriate patches as mentioned in Oracle Security Bulletin available at
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html
Vendor Information
Oracle
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html
References
Oracle
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-10269-4021872.html
Security Focus
http://www.securityfocus.com/bid/101841/info
CVE Name
CVE-2017-10269
CVE-2017-10272
CVE-2017-10267
CVE-2017-10278
CVE-2017-10266
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|