Vulnerability Name: | CVE-2013-5785 (CCN-90273) | ||||||||
Assigned: | 2013-09-18 | ||||||||
Published: | 2014-01-14 | ||||||||
Updated: | 2014-01-28 | ||||||||
Summary: | Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.6, 11.1.1.7, and 11.1.2.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security and Authentication. Per: http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html "Please refer to Doc ID My Oracle Support Note 1608683.1 for instructions on how to address this issue." | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Unknown | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-5785 Source: OSVDB Type: UNKNOWN 102111 Source: SECUNIA Type: UNKNOWN 56465 Source: CCN Type: Oracle Web site Oracle Critical Patch Update Advisory - January 2014 Source: CONFIRM Type: Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html Source: BID Type: UNKNOWN 64758 Source: CCN Type: BID-64758 RETIRED: Oracle January 2014 Critical Patch Update Multiple Vulnerabilities Source: BID Type: UNKNOWN 64819 Source: CCN Type: BID-64819 Oracle Reports Developer CVE-2013-5785 Remote Security Vulnerability Source: SECTRACK Type: UNKNOWN 1029613 Source: XF Type: UNKNOWN oracle-cpujan2014-cve20135785(90273) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |