<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="2967710.xsl"?>
<?xml-stylesheet type="text/css" href="2967708.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Security Alert for CVE-2017-10269 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Security Alert</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CVE-2017-10269</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2017-11-14T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2017-11-14T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2017-11-14T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/4021804.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>https://www.oracle.com/security-alerts/alert-cve-2017-10269.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Dmitrii Iudin aka @ret5et of ERPScan</Name>
         <Organization></Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Fusion Middleware" Type="Product Family">
            <Branch Name="Tuxedo" Type="Product Name">
               <Branch Name="11.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5433V-11.1.1">Tuxedo Version 11.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5433V-12.1.1">Tuxedo Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-5433V-12.1.3">Tuxedo Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.2" Type="Product Version">
                  <FullProductName ProductID="P-5433V-12.2.2">Tuxedo Version 12.2.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-10266</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core).  Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and  12.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Jolt to compromise Oracle Tuxedo.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Tuxedo accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-10266</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5433V-11.1.1</ProductID>
            <ProductID>P-5433V-12.1.1</ProductID>
            <ProductID>P-5433V-12.1.3</ProductID>
            <ProductID>P-5433V-12.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CVE-2017-10269</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/alert-cve-2017-10269.html</URL>
            <ProductID>P-5433V-11.1.1</ProductID>
            <ProductID>P-5433V-12.1.1</ProductID>
            <ProductID>P-5433V-12.1.3</ProductID>
            <ProductID>P-5433V-12.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-10267</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core).  Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and  12.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Jolt to compromise Oracle Tuxedo.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Tuxedo accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-10267</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5433V-11.1.1</ProductID>
            <ProductID>P-5433V-12.1.1</ProductID>
            <ProductID>P-5433V-12.1.3</ProductID>
            <ProductID>P-5433V-12.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CVE-2017-10269</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/alert-cve-2017-10269.html</URL>
            <ProductID>P-5433V-11.1.1</ProductID>
            <ProductID>P-5433V-12.1.1</ProductID>
            <ProductID>P-5433V-12.1.3</ProductID>
            <ProductID>P-5433V-12.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-10269</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core).  Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and  12.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Jolt to compromise Oracle Tuxedo.  While the vulnerability is in Oracle Tuxedo, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Tuxedo accessible data as well as  unauthorized access to critical data or complete access to all Oracle Tuxedo accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Tuxedo. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-10269</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5433V-11.1.1</ProductID>
            <ProductID>P-5433V-12.1.1</ProductID>
            <ProductID>P-5433V-12.1.3</ProductID>
            <ProductID>P-5433V-12.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CVE-2017-10269</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/alert-cve-2017-10269.html</URL>
            <ProductID>P-5433V-11.1.1</ProductID>
            <ProductID>P-5433V-12.1.1</ProductID>
            <ProductID>P-5433V-12.1.3</ProductID>
            <ProductID>P-5433V-12.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-10272</Title>
      <Notes>
         <Note Audience="All" Ordinal="4" Title="Details" Type="Details">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core).  Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and  12.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via Jolt to compromise Oracle Tuxedo.  While the vulnerability is in Oracle Tuxedo, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Tuxedo accessible data as well as  unauthorized access to critical data or complete access to all Oracle Tuxedo accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Tuxedo. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-10272</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5433V-11.1.1</ProductID>
            <ProductID>P-5433V-12.1.1</ProductID>
            <ProductID>P-5433V-12.1.3</ProductID>
            <ProductID>P-5433V-12.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CVE-2017-10269</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/alert-cve-2017-10269.html</URL>
            <ProductID>P-5433V-11.1.1</ProductID>
            <ProductID>P-5433V-12.1.1</ProductID>
            <ProductID>P-5433V-12.1.3</ProductID>
            <ProductID>P-5433V-12.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-10278</Title>
      <Notes>
         <Note Audience="All" Ordinal="5" Title="Details" Type="Details">Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Security).  Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and  12.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Jolt to compromise Oracle Tuxedo.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Tuxedo accessible data as well as  unauthorized update, insert or delete access to some of Oracle Tuxedo accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Tuxedo. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-10278</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5433V-11.1.1</ProductID>
            <ProductID>P-5433V-12.1.1</ProductID>
            <ProductID>P-5433V-12.1.3</ProductID>
            <ProductID>P-5433V-12.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CVE-2017-10269</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/alert-cve-2017-10269.html</URL>
            <ProductID>P-5433V-11.1.1</ProductID>
            <ProductID>P-5433V-12.1.1</ProductID>
            <ProductID>P-5433V-12.1.3</ProductID>
            <ProductID>P-5433V-12.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
