Vulnerability CVE-2008-1827


Published: 2008-04-16   Modified: 2012-02-12

Description:
Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 and 12.0.4 have unknown impact and attack vectors related to (a) Advanced Pricing component, aka (1) APP02, (2) APP03, and (3) APP09; (b) Application Object Library component, aka (4) APP04, (5) APP07, and (6) APP11; (c) Applications Manager component, aka (7) APP06; (d) and Applications Technology Stack component, aka (8) APP08.

Type:

CWE-noinfo

Vendor: Oracle
Product: E-business suite 12 
Version: 12.0.4;
Product: E-business suite 11i 
Version: 11.5.10.2;

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://www.oracle.com/technetwork/topics/security/cpuapr2008-082075.html
http://www.securityfocus.com/archive/1/491024/100/0/threaded
http://www.securitytracker.com/id?1019855
http://www.vupen.com/english/advisories/2008/1233/references
http://www.vupen.com/english/advisories/2008/1267/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/41858
https://exchange.xforce.ibmcloud.com/vulnerabilities/42056
https://exchange.xforce.ibmcloud.com/vulnerabilities/42057
https://exchange.xforce.ibmcloud.com/vulnerabilities/42059
https://exchange.xforce.ibmcloud.com/vulnerabilities/42060
https://exchange.xforce.ibmcloud.com/vulnerabilities/42061
https://exchange.xforce.ibmcloud.com/vulnerabilities/42062
https://exchange.xforce.ibmcloud.com/vulnerabilities/42063
https://exchange.xforce.ibmcloud.com/vulnerabilities/42064

Related CVE
CVE-2018-12023
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provid...
CVE-2019-2556
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon...
CVE-2019-2555
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon...
CVE-2019-2554
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon...
CVE-2019-2553
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon...
CVE-2019-2552
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon...
CVE-2019-2550
Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Logoff Page). The supported version that is affected is 12.0.2. Easily exploitable vulnerability allows unauthenticated attacker wi...
CVE-2019-2549
Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Logoff Page). The supported version that is affected is 12.0.2. Easily exploitable vulnerability allows unauthenticated attacker wi...

Copyright 2019, cxsecurity.com

 

Back to Top