| Vulnerability Name: | CVE-2009-1005 (CCN-50055) | ||||||||
| Assigned: | 2009-04-14 | ||||||||
| Published: | 2009-04-14 | ||||||||
| Updated: | 2012-10-23 | ||||||||
| Summary: | Unspecified vulnerability in the Oracle Data Service Integrator (AquaLogic Data Services Platform) component in BEA Product Suite 10.3.0, 3.2, 3.0.1, and 3.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors. | ||||||||
| CVSS v3 Severity: | 4.2 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 4.1 Medium (CVSS v2 Vector: AV:L/AC:M/Au:S/C:P/I:P/A:P) 3.0 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: MITRE Type: CNA CVE-2009-1005 Source: OSVDB Type: UNKNOWN 53760 Source: CCN Type: SECTRACK ID: 1022059 Oracle WebLogic Server and Portal Bugs Let Remote Users Access and Modify Data and Cause Denial of Service Conditions Source: CCN Type: Oracle Critical Patch Update Advisory - April 2009 Oracle Critical Patch Update Advisory - April 2009 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuapr2009-099563.html Source: CCN Type: Oracle SECURITY ADVISORY (CVE-2009-1005) Elevation of privilege vulnerability in Oracle Data Service Integrator and AquaLogic Data Services Platform Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technology/deploy/security/wls-security/1005.html Source: CCN Type: OSVDB ID: 53760 Oracle BEA Oracle Data Service Integrator (AquaLogic Data Services Platform) Source: BID Type: UNKNOWN 34461 Source: CCN Type: BID-34461 Oracle April 2009 Critical Patch Update Multiple Vulnerabilities Source: SECTRACK Type: UNKNOWN 1022059 Source: CERT Type: US Government Resource TA09-105A Source: XF Type: UNKNOWN oracle-weblogic-odsi-priv-escalation(50055) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||