Synced 19 Jun 2026 07:34 UTC Account
← All products

CVE-2007-2170

HIGH severity · CVSS 9.4
9.4CVSS HIGH

Summary

The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges required
User interaction
Confidentiality impactNone
Integrity impact
Availability impact
Exploit probability (EPSS)4%

AV:N/AC:L/Au:N/C:N/I:C/A:C

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html ↗