| Vulnerability Name: | CVE-2013-3749 (CCN-85673) | ||||||||
| Assigned: | 2013-07-16 | ||||||||
| Published: | 2013-07-16 | ||||||||
| Updated: | 2017-08-29 | ||||||||
| Summary: | Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Logging. Note: the previous information is from the July 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to storage of credentials in the (1) FND_LOG_MESSAGES database table or (2) log files by "native login pages." | ||||||||
| CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N)
| ||||||||
| CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N) 2.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
2.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-3749 Source: OSVDB Type: UNKNOWN 95286 Source: CCN Type: SA54222 Oracle E-Business Suite Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 54222 Source: CCN Type: US-CERT VU#826463 Oracle E-Business Suite password disclosure vulnerability Source: CERT-VN Type: US Government Resource VU#826463 Source: CCN Type: Oracle Web Site Oracle Critical Patch Update - July 2013 Source: CONFIRM Type: Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html Source: BID Type: UNKNOWN 61268 Source: CCN Type: BID-61268 Oracle E-Business Suite CVE-2013-3749 Remote Password Disclosure Vulnerability Source: SECTRACK Type: UNKNOWN 1028799 Source: XF Type: UNKNOWN oracle-cpujuly2013-cve20133749(85673) Source: XF Type: UNKNOWN oracle-cpujuly2013-cve20133749(85673) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||