Vulnerability Name: CVE-2011-2257 (CCN-68644) Assigned: 2011-07-20 Published: 2011-07-20 Updated: 2011-10-05 Summary: Unspecified vulnerability in the Database Target Type Menus component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6, 10.2.0.5, and 11.1.0.1; allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. CVSS v3 Severity: 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P )5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2011-2257 Source: CCN Type: Oracle Critical Patch Update Advisory - July 2011Oracle Critical Patch Update Advisory - July 2011 Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.oracle.com/technetwork/topics/security/cpujuly2011-313328.html Source: CCN Type: OSVDB ID: 73926Oracle Enterprise Manager Grid Control Database Target Type Menus Unspecified Remote Issue Source: CCN Type: BID-48751Oracle Database Target Type Menus CVE-2011-2257 Remote Security Vulnerability Source: CERT Type: US Government ResourceTA11-201A Source: XF Type: UNKNOWNora-dbserv-corerdbms-unspec-var8(68644) Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.5:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.1.0.7:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.2:*:*:*:*:*:*:* Configuration 2 :cpe:/a:oracle:enterprise_manager_grid_control:10.1.0.6:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:10.2.0.5:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:11.1.0.1:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:oracle:database_server:10.2.0.5:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:10.2.0.5:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.2:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
oracle database server 10.1.0.5
oracle database server 10.2.0.3
oracle database server 10.2.0.4
oracle database server 10.2.0.5
oracle database server 11.1.0.7
oracle database server 11.2.0.1
oracle database server 11.2.0.2
oracle enterprise manager grid control 10.1.0.6
oracle enterprise manager grid control 10.2.0.5
oracle enterprise manager grid control 11.1.0.1
oracle database server 10.2.0.5
oracle enterprise manager grid control 10.2.0.5
oracle database server 11.2.0.2