| Vulnerability Name: | CVE-2015-4796 (CCN-107285) | ||||||||
| Assigned: | 2015-10-20 | ||||||||
| Published: | 2015-10-20 | ||||||||
| Updated: | 2016-12-24 | ||||||||
| Summary: | Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4888. Per Advisory: <a href="http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html">This issue impacts the Windows platform only.</a> | ||||||||
| CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C) 6.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: MITRE Type: CNA CVE-2015-4796 Source: CCN Type: Oracle Critical Patch Update Advisory - October 2015 Oracle Critical Patch Update Advisory - October 2015 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html Source: BID Type: UNKNOWN 77193 Source: CCN Type: BID-77193 Oracle Database Server CVE-2015-4796 Remote Security Vulnerability Source: SECTRACK Type: UNKNOWN 1033883 Source: XF Type: UNKNOWN oracle-cpuoct2015-cve20154796(107285) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||