APP: Oracle Tuxedo Jolt Protocol CVE-2017-10278 Heap Buffer Overflow

A heap buffer vulnerability exists in Oracle's Tuxedo and PeopleSoft products. Successful exploitation will result in arbitrary code execution with the privileges of the server process.

Extended Description

Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 11.1.1, 12.1.1, 12.1.3 and 12.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Jolt to compromise Oracle Tuxedo. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Tuxedo accessible data as well as unauthorized update, insert or delete access to some of Oracle Tuxedo accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Tuxedo. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).

Affected Products

Oracle tuxedo

Short Name
APP:ORACLE:CVE-2017-10278-OF
Severity
Major
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
Buffer CVE-2017-10278 Heap Jolt Oracle Overflow Protocol Tuxedo
Release Date
12/12/2017
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3337
Port
TCP/9034-9038
False Positive
Unknown
Vendors

Oracle

CVSS Score

6.8

Found a potential security threat?