Vulnerability Name: | CVE-2015-4811 (CCN-107304) | ||||||||
Assigned: | 2015-10-20 | ||||||||
Published: | 2015-10-20 | ||||||||
Updated: | 2016-12-07 | ||||||||
Summary: | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via vectors related to Outside In PDF Export SDKutside In PDF Export SDK, a different vulnerability than CVE-2015-4809. Per Advisory: <a href="http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html">Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS v2.0 Base Score would increase to 6.8.</a> | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 1.5 Low (CVSS v2 Vector: AV:L/AC:M/Au:S/C:N/I:N/A:P) 1.1 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2015-4811 Source: CCN Type: IBM Security Bulletin 1969427 Four vulnerabilities exist in IBM FileNet Content Manager and IBM Content Foundation (CVE-2015-4809, CVE-2015-4811, CVE-2015-4877, CVE-2015-4878) Source: CCN Type: IBM Security Bulletin 1975750 (WebSphere Portal) Vulnerabilities in Oracle Outside In Technology affect IBM WebSphere Portal Source: CCN Type: Oracle Critical Patch Update Advisory - October 2015 Oracle Critical Patch Update Advisory - October 2015 Source: CONFIRM Type: Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html Source: BID Type: UNKNOWN 77138 Source: CCN Type: BID-77138 Oracle Fusion Middleware CVE-2015-4811 Local Security Vulnerability Source: SECTRACK Type: UNKNOWN 1033898 Source: XF Type: UNKNOWN oracle-cpuoct2015-cve20154811(107304) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |