Vulnerability Name: CVE-2014-6545 (CCN-97068) Assigned: 2014-10-14 Published: 2014-10-14 Updated: 2015-11-17 Summary: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6453 , CVE-2014-6467 , and CVE-2014-6560 . CVSS v3 Severity: 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C )6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C )6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2014-6545 Source: CCN Type: Oracle Critical Patch Update Advisory - October 2014Oracle Critical Patch Update Advisory - October 2014 Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html Source: BID Type: UNKNOWN70467 Source: CCN Type: BID-70467Oracle Database Server CVE-2014-6545 Remote Security Vulnerability Source: XF Type: UNKNOWNoracle-cpuoct2014-cve20146545(97068) Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:database_server:11.1.0.7:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:oracle:database_server:11.1.0.7:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
oracle database server 11.1.0.7
oracle database server 11.2.0.3
oracle database server 11.2.0.4
oracle database server 12.1.0.1
oracle database server 12.1.0.2
oracle database server 11.1.0.7
oracle database server 11.2.0.3
oracle database server 12.1.0.1
oracle database server 11.2.0.4
oracle database server 12.1.0.2