Vulnerability Name: CVE-2015-2629 (CCN-104652) Assigned: 2015-07-14 Published: 2015-07-14 Updated: 2017-09-22 Summary: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-0457 . Per Advisory: <a href="http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html">The CVSS score is 9.0 only on Windows for Database versions prior to 12c. The CVSS is 6.5 (Confidentiality, Integrity and Availability is "Partial+") for Database 12c on Windows and for all versions of Database on Linux, Unix and other platforms.</a> CVSS v3 Severity: 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C )6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C )6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2015-2629 Source: SUSE Type: UNKNOWNSUSE-SU-2015:1353 Source: CCN Type: IBM Security Bulletin 1968013IBM OpenPages Platform with Database vulnerabilities. Source: CCN Type: Oracle Critical Patch Update - July 2015Oracle Critical Patch Update - July 2015 Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html Source: SECTRACK Type: UNKNOWN1032903 Source: XF Type: UNKNOWNoracle-cpujuly2015-cve20152629(104652) Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:database_server:11.1.0.7:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:oracle:database_server:11.1.0.7:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:* AND cpe:/a:ibm:openpages_grc_platform:6.2.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:openpages_grc_platform:7.0.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:openpages_grc_platform:6.2.0.0:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
oracle database server 11.1.0.7
oracle database server 11.2.0.3
oracle database server 11.2.0.4
oracle database server 12.1.0.1
oracle database server 12.1.0.2
oracle database server 11.1.0.7
oracle database server 11.2.0.3
oracle database server 12.1.0.1
oracle database server 11.2.0.4
oracle database server 12.1.0.2
ibm openpages grc platform 6.2.1.0
ibm openpages grc platform 7.0.0.0
ibm openpages grc platform 6.2.0.0