9.1
CVE-2017-3508
- EPSS 2.27%
- Veröffentlicht 24.04.2017 19:59:03
- Zuletzt bearbeitet 13.05.2026 00:24:29
- Erkennungen
Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration). Supported versions that are affected are 1.0, 1.1, 14.2, 15.1, 15.2, 16.1 and 16.2. Easily "exploitable" vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Gateway. While the vulnerability is in Primavera Gateway, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Primavera Gateway. CVSS 3.0 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Primavera Gateway Version 1.0
Oracle ≫ Primavera Gateway Version 1.1
Oracle ≫ Primavera Gateway Version 14.2
Oracle ≫ Primavera Gateway Version 15.1
Oracle ≫ Primavera Gateway Version 15.2
Oracle ≫ Primavera Gateway Version 16.1
Oracle ≫ Primavera Gateway Version 16.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.27% | 0.808 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.1 | 2.3 | 6 |
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
http://www.securitytracker.com/id/1038289
http://www.securityfocus.com/bid/97883
http://www.securityfocus.com/bid/97889