| Vulnerability Name: | CVE-2016-3536 (CCN-115185) | ||||||||||||
| Assigned: | 2016-07-19 | ||||||||||||
| Published: | 2016-07-19 | ||||||||||||
| Updated: | 2017-09-01 | ||||||||||||
| Summary: | Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Deliverables. Note: the previous information is from the July 2016 CPU. Oracle has not commented on third-party claims that this issue involves multiple cross-site scripting (XSS) vulnerabilities, which allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||||||||||||
| CVSS v3 Severity: | 8.2 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N) 7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 7.0 High (CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-noinfo | ||||||||||||
| Vulnerability Consequences: | Other | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-3536 Source: CCN Type: Oracle CPUJul2016 Oracle Critical Patch Update Advisory - July 2016 Source: CONFIRM Type: Patch, Vendor Advisory http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html Source: BID Type: Third Party Advisory, VDB Entry 91787 Source: CCN Type: BID-91787 Oracle July 2016 Critical Patch Update Multiple Vulnerabilities Source: BID Type: UNKNOWN 91857 Source: SECTRACK Type: UNKNOWN 1036403 Source: XF Type: UNKNOWN oracle-cpujul2016-cve20163536(115185) Source: MISC Type: Third Party Advisory https://www.onapsis.com/blog/oracle-fixes-record-276-vulnerabilities-july-2016 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||