Vulnerability Name: | CVE-2014-0391 (CCN-90275) | ||||||||
Assigned: | 2013-12-12 | ||||||||
Published: | 2014-01-14 | ||||||||
Updated: | 2016-11-17 | ||||||||
Summary: | Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.0, and 11.1.2.1 allows remote attackers to affect confidentiality via unknown vectors related to End User Self Service. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-0391 Source: OSVDB Type: UNKNOWN 102099 Source: SECUNIA Type: UNKNOWN 56459 Source: CCN Type: Oracle Web site Oracle Critical Patch Update Advisory - January 2014 Source: CONFIRM Type: Patch, Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html Source: BID Type: Third Party Advisory, VDB Entry 64758 Source: CCN Type: BID-64758 RETIRED: Oracle January 2014 Critical Patch Update Multiple Vulnerabilities Source: BID Type: Third Party Advisory, VDB Entry 64829 Source: CCN Type: BID-64829 Oracle Identity Manager CVE-2014-0391 Remote Security Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1029613 Source: XF Type: UNKNOWN oracle-cpujan2014-cve20140391(90275) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |