| Vulnerability Name: | CVE-2010-2390 (CCN-62408) | ||||||||
| Assigned: | 2010-10-12 | ||||||||
| Published: | 2010-10-12 | ||||||||
| Updated: | 2010-11-11 | ||||||||
| Summary: | Unspecified vulnerability in the Database Control component in EM Console in Oracle Database Server 10.1.0.5 and 10.2.0.3, Oracle Fusion Middleware 10.1.2.3 and 10.1.4.3, and Enterprise Manager Grid Control allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2010-2390 Source: CCN Type: SA41762 Oracle Fusion Middleware Products Multiple Vulnerabilities Source: CCN Type: SA41794 Oracle Enterprise Manager Grid Control Unspecified Vulnerability Source: CCN Type: SA41815 Oracle Database Multiple Vulnerabilities Source: CCN Type: Oracle Critical Patch Update Advisory - October 2010 Oracle Critical Patch Update Advisory - October 2010 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html Source: CCN Type: OSVDB ID: 70063 Oracle Multiple Products EM Console HTTP Request Handling Remote Overflow Source: CCN Type: BID-43945 Oracle Enterprise Manager Grid Control CVE-2010-2390 Remote EM Console Vulnerability Source: CERT Type: US Government Resource TA10-287A Source: XF Type: UNKNOWN odb-emcon-unspec(62408) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||