Vulnerability Name: | CVE-2016-0451 (CCN-109784) | ||||||||
Assigned: | 2015-12-09 | ||||||||
Published: | 2016-01-19 | ||||||||
Updated: | 2017-01-03 | ||||||||
Summary: | Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0452. Per Oracle: The CVSS score is 10.0 only on Windows for Database versions prior to 12c. The CVSS is 7.5 (Confidentiality, Integrity and Availability is "Partial+") for Database 12c on Windows and for all versions of Database on Linux, Unix and other platforms. | ||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
4.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2016-0451 Source: CCN Type: Oracle Critical Patch Update Advisory - January 2016 Oracle Critical Patch Update Advisory - January 2016 Source: CONFIRM Type: Vendor Advisory http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html Source: BID Type: Third Party Advisory, VDB Entry 81125 Source: MISC Type: Third Party Advisory, VDB Entry http://www.zerodayinitiative.com/advisories/ZDI-16-022 Source: XF Type: UNKNOWN oracle-cpujan2016-cve20160451(109784) Source: MISC Type: Exploit, Third Party Advisory https://redr2e.com/cve-to-poc-cve-2016-0451/ Source: CCN Type: ZDI-16-022 Oracle GoldenGate File Upload Remote Code Execution Vulnerability | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |