Vulnerability Name: | CVE-2011-2232 (CCN-68628) | ||||||||
Assigned: | 2011-07-20 | ||||||||
Published: | 2011-07-20 | ||||||||
Updated: | 2011-10-05 | ||||||||
Summary: | Unspecified vulnerability in the XML Developer Kit component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 11.1.0.7, and 11.2.0.1, and Oracle Fusion Middleware 10.1.3.5, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. Per: http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.html 'Component of this XML DB security fix in Fusion Middleware products is "XML Developers Kit". The sub-component is "XML Parser".' | ||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 4.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
4.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-2232 Source: CCN Type: Oracle Critical Patch Update Advisory - July 2011 Oracle Critical Patch Update Advisory - July 2011 Source: CONFIRM Type: Patch, Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.html Source: CCN Type: OSVDB ID: 73948 Oracle Database XML Developer Kit Unspecified Remote Issue Source: CCN Type: BID-48755 Oracle Application Server XML Developer Kit CVE-2011-2232 Remote Security Vulnerability Source: CERT Type: US Government Resource TA11-201A Source: XF Type: UNKNOWN ora-dbservfm-xmkdk-unspec(68628) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |