S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-3528 Scanner

Detects 'Open Redirect' vulnerability in Oracle Corporation Applications Framework affects v. 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-3528
5.4
CVSS

Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Applications Frameworkby Oracle Corporation
12.1.3
Updated Aug 22, 2026View on NVD →
Detail

The Oracle Corporation Applications Framework is a software component of the Oracle E-Business Suite that is used by businesses for various purposes such as financial management, supply chain management, customer relationship management, and human resource management. The framework provides a foundation for the customizations developed within the Oracle E-Business Suite and helps businesses to streamline their operations and improve efficiency. It has an extensive library of pre-built Oracle application components that can be customized and extended according to business requirements, which makes it a popular choice among businesses worldwide.

However, the Oracle Corporation Applications Framework has been found to have a critical vulnerability, CVE-2017-3528, that affects the Popup windows subcomponent. This vulnerability can be exploited by an unauthenticated attacker who has network access via HTTP. The attack can be initiated by a victim who clicks on a malicious link or opens a malicious document which triggers the popup windows. Since the vulnerability is easily exploitable and requires only human interaction, it poses a serious threat to businesses that use the Oracle E-Business Suite.

If the vulnerability is successfully exploited, unauthorized access to sensitive data can be gained. This can lead to an attacker being able to perform unauthorized updates, inserts, or deletes of data accessed by the Oracle Applications Framework. The impact of such attacks can be extensive and can result in a loss of data integrity and confidentiality, as well as availability issues that could compromise business operations and reputation.

The s4e.io platform provides businesses with the tools and knowledge necessary to quickly and easily identify vulnerabilities in their digital assets. Using their advanced features, businesses can gain comprehensive insights into their security posture and take proactive steps to protect against potential threats. With s4e.io, businesses can stay ahead of the curve and ensure the security and privacy of their valuable data.

 

REFERENCES

Solution Advice

To protect against this vulnerability, businesses that use the Oracle E-Business Suite should take the following precautions:

  • Ensure that the latest security patches are installed as soon as they are released by Oracle.
  • Implement a web application firewall to monitor and block suspicious traffic.
  • Educate employees about the risks associated with clicking on links or opening attachments from unknown sources.
  • Establish access controls to limit user privileges to only what is necessary to perform their job functions.
  • Conduct regular vulnerability assessments and penetration testing to identify and fix vulnerabilities before they can be exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-3528 scanner - Open Redirect vulnerability in Oracle Corporation Applications Framework | S4E