Vulnerability Name:

CVE-2010-3564 (CCN-62461)

Assigned:2010-10-12
Published:2010-10-12
Updated:2017-09-19
Summary:Unspecified vulnerability in the Oracle Communications Messaging Server (Sun Java System Messaging Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Webmail.
Note: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that the Kerberos implementation does not properly check AP-REQ requests, which allows attackers to cause a denial of service in the JVM.
Note: CVE has not investigated the apparent discrepancy between the two vendors regarding the consequences of this issue.
CVSS v3 Severity:6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
4.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
4.0 Medium (REDHAT CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P)
3.0 Low (REDHAT Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2010-3564

Source: HP
Type: UNKNOWN
SSRT100333

Source: FEDORA
Type: UNKNOWN
FEDORA-2010-16312

Source: FEDORA
Type: UNKNOWN
FEDORA-2010-16294

Source: FEDORA
Type: UNKNOWN
FEDORA-2010-16240

Source: CCN
Type: RHSA-2010-0768
Important: java-1.6.0-openjdk security and bug fix update

Source: CCN
Type: RHSA-2010-0865
Important: java-1.6.0-openjdk security and bug fix update

Source: CCN
Type: SA41831
Oracle Communications Messaging Server Webmail Unspecified Vulnerability

Source: SECUNIA
Type: Vendor Advisory
41972

Source: CCN
Type: SA42377
Hitachi Products Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
42377

Source: GENTOO
Type: UNKNOWN
GLSA-201406-32

Source: CONFIRM
Type: UNKNOWN
http://support.avaya.com/css/P8/documents/100114327

Source: CONFIRM
Type: UNKNOWN
http://support.avaya.com/css/P8/documents/100123193

Source: CONFIRM
Type: UNKNOWN
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html

Source: CCN
Type: Oracle Critical Patch Update Advisory - October 2010
Oracle Critical Patch Update Advisory - October 2010

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html

Source: CCN
Type: OSVDB ID: 70072
Oracle Communications Messaging Server Webmail Kerberos AP-REQ Remote DoS

Source: REDHAT
Type: UNKNOWN
RHSA-2010:0768

Source: REDHAT
Type: UNKNOWN
RHSA-2010:0865

Source: BID
Type: UNKNOWN
43963

Source: CCN
Type: BID-43963
Oracle Communications Messaging Server CVE-2010-3564 Webmail Remote Vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-1010-1

Source: CERT
Type: US Government Resource
TA10-287A

Source: VUPEN
Type: Vendor Advisory
ADV-2010-3086

Source: XF
Type: UNKNOWN
osps-mserver-webmail-unspec(62461)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:12398

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:sun_products_suite:7.0:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:communications_messaging_server:7.0:*:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:5:*:client:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:6:*:server:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:6:*:workstation:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:6:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20103564
    V
    CVE-2010-3564
    2015-11-16
    oval:org.mitre.oval:def:12398
    V
    HP-UX Running Java, Remote Execution of Arbitrary Code, Disclosure of Information, and Other Vulnerabilities.
    2015-04-20
    oval:org.mitre.oval:def:13305
    P
    USN-1010-1 -- openjdk-6, openjdk-6b18 vulnerabilities
    2014-06-30
    oval:org.mitre.oval:def:23563
    P
    ELSA-2010:0865: java-1.6.0-openjdk security and bug fix update (Important)
    2014-05-26
    oval:org.mitre.oval:def:22962
    P
    ELSA-2010:0768: java-1.6.0-openjdk security and bug fix update (Important)
    2014-05-26
    oval:org.mitre.oval:def:21716
    P
    RHSA-2010:0768: java-1.6.0-openjdk security and bug fix update (Important)
    2014-02-24
    oval:org.mitre.oval:def:22285
    P
    RHSA-2010:0865: java-1.6.0-openjdk security and bug fix update (Important)
    2014-02-24
    oval:com.redhat.rhsa:def:20100865
    P
    RHSA-2010:0865: java-1.6.0-openjdk security and bug fix update (Important)
    2010-11-10
    oval:com.redhat.rhsa:def:20100768
    P
    RHSA-2010:0768: java-1.6.0-openjdk security and bug fix update (Important)
    2010-10-13
    BACK
    oracle sun products suite 7.0
    oracle communications messaging server 7.0
    redhat enterprise linux 5
    redhat enterprise linux 5
    redhat enterprise linux 6
    redhat enterprise linux 6
    redhat enterprise linux desktop 6
    redhat enterprise linux hpc node 6