{"api_version":"1","generated_at":"2026-07-23T06:56:33+00:00","cve":"CVE-2017-3311","urls":{"html":"https://cve.report/CVE-2017-3311","api":"https://cve.report/api/cve/CVE-2017-3311.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-3311","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-3311"},"summary":{"title":"CVE-2017-3311","description":"Vulnerability in the Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps). Supported versions that are affected are 12.5.0.3, 12.5.0.2 and 12.4.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Application Testing Suite accessible data. CVSS v3.0 Base Score 5.3 (Integrity impacts).","state":"PUBLISHED","assigner":"oracle","published_at":"2017-01-27 22:59:04","updated_at":"2025-04-20 01:37:25"},"problem_types":["NVD-CWE-noinfo","CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html","name":"http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Oracle Critical Patch Update - January 2017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/95584","name":"http://www.securityfocus.com/bid/95584","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Application Testing Suite CVE-2017-3311 Remote Security Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id/1037633","name":"http://www.securitytracker.com/id/1037633","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oracle Enterprise Manager Grid Control Multiple Bugs Let Remote Users Modify Data and Gain Elevated Privileges and Let Remote Authenticated Users Access Data and Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-3311","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-3311","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Oracle","product":"Application Testing Suite","version":"affected 12.5.0.3","platforms":[]},{"source":"CNA","vendor":"Oracle","product":"Application Testing Suite","version":"affected 12.5.0.2","platforms":[]},{"source":"CNA","vendor":"Oracle","product":"Application Testing Suite","version":"affected 12.4.0.2","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"3311","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"application_testing_suite","cpe6":"12.4.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"3311","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"application_testing_suite","cpe6":"12.5.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"3311","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"application_testing_suite","cpe6":"12.5.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T14:23:34.232Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"95584","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/95584"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html"},{"name":"1037633","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1037633"}],"title":"CVE Program Container"},{"metrics":[{"other":{"content":{"id":"CVE-2017-3311","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2024-10-08T20:04:49.786988Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-10-08T20:35:03.119Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"Application Testing Suite","vendor":"Oracle","versions":[{"status":"affected","version":"12.5.0.3"},{"status":"affected","version":"12.5.0.2"},{"status":"affected","version":"12.4.0.2"}]}],"datePublic":"2017-01-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Vulnerability in the Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps). Supported versions that are affected are 12.5.0.3, 12.5.0.2 and 12.4.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Application Testing Suite accessible data. CVSS v3.0 Base Score 5.3 (Integrity impacts)."}],"problemTypes":[{"descriptions":[{"description":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-25T09:57:01.000Z","orgId":"43595867-4340-4103-b7a2-9a5208d29a85","shortName":"oracle"},"references":[{"name":"95584","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/95584"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html"},{"name":"1037633","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1037633"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert_us@oracle.com","ID":"CVE-2017-3311","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Application Testing Suite","version":{"version_data":[{"version_value":"12.5.0.3"},{"version_value":"12.5.0.2"},{"version_value":"12.4.0.2"}]}}]},"vendor_name":"Oracle"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Vulnerability in the Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps). Supported versions that are affected are 12.5.0.3, 12.5.0.2 and 12.4.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Application Testing Suite accessible data. CVSS v3.0 Base Score 5.3 (Integrity impacts)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}]},"references":{"reference_data":[{"name":"95584","refsource":"BID","url":"http://www.securityfocus.com/bid/95584"},{"name":"http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html","refsource":"CONFIRM","url":"http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html"},{"name":"1037633","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037633"}]}}}},"cveMetadata":{"assignerOrgId":"43595867-4340-4103-b7a2-9a5208d29a85","assignerShortName":"oracle","cveId":"CVE-2017-3311","datePublished":"2017-01-27T22:01:00.000Z","dateReserved":"2016-12-06T00:00:00.000Z","dateUpdated":"2024-10-08T20:35:03.119Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-01-27 22:59:04","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["NVD-CWE-noinfo","CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:application_testing_suite:12.4.0.2:*:*:*:*:*:*:*","matchCriteriaId":"08F3E8E4-BD91-4220-B710-960A45C232D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:application_testing_suite:12.5.0.2:*:*:*:*:*:*:*","matchCriteriaId":"62E818A9-663D-4AFB-B3D6-686CE4DB9676"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:application_testing_suite:12.5.0.3:*:*:*:*:*:*:*","matchCriteriaId":"17EA8B91-7634-4636-B647-1049BA7CA088"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"3311","Ordinal":"1","Title":"CVE-2017-3311","CVE":"CVE-2017-3311","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"3311","Ordinal":"1","NoteData":"Vulnerability in the Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps). Supported versions that are affected are 12.5.0.3, 12.5.0.2 and 12.4.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Application Testing Suite accessible data. CVSS v3.0 Base Score 5.3 (Integrity impacts).","Type":"Description","Title":"CVE-2017-3311"},{"CveYear":"2017","CveId":"3311","Ordinal":"2","NoteData":"2017-01-27","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"3311","Ordinal":"3","NoteData":"2017-07-25","Type":"Other","Title":"Modified"}]}}}