Vulnerability Name: | CVE-2014-4293 (CCN-97075) |
Assigned: | 2014-10-14 |
Published: | 2014-10-14 |
Updated: | 2016-05-11 |
Summary: | Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4296, CVE-2014-4297, CVE-2014-4310, CVE-2014-6547, and CVE-2014-6477.
|
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): Required | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N) 3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
Vulnerability Type: | CWE-noinfo
|
Vulnerability Consequences: | Obtain Information |
References: | Source: MITRE Type: CNA CVE-2014-4293
Source: CCN Type: IBM Security Bulletin 1690427 IBM OpenPages Platform with Database vulnerabilities.
Source: CCN Type: Oracle Critical Patch Update Advisory - October 2014 Oracle Critical Patch Update Advisory - October 2014
Source: CONFIRM Type: Patch, Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html
Source: BID Type: UNKNOWN 70490
Source: CCN Type: BID-70490 Oracle Database Server CVE-2014-4293 Remote Security Vulnerability
Source: XF Type: UNKNOWN oracle-cpuoct2014-cve20144293(97075)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:oracle:database_server:11.1.0.7:*:*:*:*:*:*:*OR cpe:/a:oracle:database_server:11.2.0.3:*:*:*:*:*:*:*OR cpe:/a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:*OR cpe:/a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:*OR cpe:/a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:oracle:database_server:11.1.0.7:*:*:*:*:*:*:*OR cpe:/a:oracle:database_server:11.2.0.3:*:*:*:*:*:*:*OR cpe:/a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:*OR cpe:/a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:*OR cpe:/a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:*AND cpe:/a:ibm:openpages_grc_platform:6.2.1.0:*:*:*:*:*:*:*OR cpe:/a:ibm:openpages_grc_platform:7.0.0.0:*:*:*:*:*:*:*OR cpe:/a:ibm:openpages_grc_platform:6.2.0.0:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |
oracle database server 11.1.0.7
oracle database server 11.2.0.3
oracle database server 11.2.0.4
oracle database server 12.1.0.1
oracle database server 12.1.0.2
oracle database server 11.1.0.7
oracle database server 11.2.0.3
oracle database server 12.1.0.1
oracle database server 11.2.0.4
oracle database server 12.1.0.2
ibm openpages grc platform 6.2.1.0
ibm openpages grc platform 7.0.0.0
ibm openpages grc platform 6.2.0.0