Vulnerability Name: | CVE-2014-6541 (CCN-100069) | ||||||||
Assigned: | 2014-09-17 | ||||||||
Published: | 2015-01-20 | ||||||||
Updated: | 2016-11-28 | ||||||||
Summary: | Unspecified vulnerability in the Recovery component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality via vectors related to DBMS_IR. Per: http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html This vulnerability is only applicable on a Windows operating system. The CVSS score is 6.3 for Database versions prior to 12c. The CVSS is 3.5 (Confidentiality is "Partial+") for Database 12c. | ||||||||
CVSS v3 Severity: | 4.8 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 6.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:N/A:N) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:N/A:N/E:U/RL:OF/RC:C)
4.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-6541 Source: CCN Type: IBM Security Bulletin 1883820 IBM OpenPages Platform with Database vulnerabilities Source: CCN Type: Oracle Critical Patch Update Advisory - January 2015 Oracle Critical Patch Update Advisory - January 2015 Source: CONFIRM Type: Patch, Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html Source: BID Type: UNKNOWN 72158 Source: CCN Type: BID-72158 Oracle Database Server CVE-2014-6541 Remote Security Vulnerability Source: SECTRACK Type: UNKNOWN 1031572 Source: XF Type: UNKNOWN oracle-cpujan2015-cve20146541(100069) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |