Vulnerability Name: CVE-2016-3490 (CCN-115203) Assigned: 2016-07-19 Published: 2016-07-19 Updated: 2017-09-01 Summary: Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0, and 6.4.1 allows remote authenticated users to affect confidentiality via vectors related to Database. CVSS v3 Severity: 3.0 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N )2.6 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): HighPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): LowIntegrity (I): NoneAvailibility (A): None
3.0 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N )2.6 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N/E:U/RL:O/RC:C )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): HighPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): LowIntegrity (I): NoneAvailibility (A): None
CVSS v2 Severity: 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:N/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): HighAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Obtain Information References: Source: MITRE Type: CNACVE-2016-3490 Source: CCN Type: Oracle CPUJul2016Oracle Critical Patch Update Advisory - July 2016 Source: CONFIRM Type: Patch, Vendor Advisoryhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html Source: BID Type: Third Party Advisory, VDB Entry91787 Source: CCN Type: BID-91787Oracle July 2016 Critical Patch Update Multiple Vulnerabilities Source: BID Type: UNKNOWN92024 Source: CCN Type: BID-92024Oracle Transportation Management CVE-2016-3490 Remote Security Vulnerability Source: SECTRACK Type: UNKNOWN1036402 Source: XF Type: UNKNOWNoracle-cpujul2016-cve20163490(115203) Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:transportation_management:6.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.1:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.2:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.3:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.4:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.5:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.6:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.4.1:*:*:*:*:*:*:* Configuration 2 :cpe:/a:oracle:transportation_management:6.3.0:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.1:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.2:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.3:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.4:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.5:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.6:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:transportation_management:6.4.1:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
oracle transportation management 6.3.0
oracle transportation management 6.3.1
oracle transportation management 6.3.2
oracle transportation management 6.3.3
oracle transportation management 6.3.4
oracle transportation management 6.3.5
oracle transportation management 6.3.6
oracle transportation management 6.3.7
oracle transportation management 6.4.0
oracle transportation management 6.4.1
oracle transportation management 6.3.0
oracle transportation management 6.3.1
oracle transportation management 6.3.2
oracle transportation management 6.3.3
oracle transportation management 6.3.4
oracle transportation management 6.3.5
oracle transportation management 6.3.6
oracle transportation management 6.3.7
oracle transportation management 6.4.0
oracle transportation management 6.4.1