These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2017-3252 is a medium-severity Oracle Java vulnerability affecting JAAS in specific Java SE, Java SE Embedded, and JRockit releases. According to the supplied NVD record, exploitation is difficult and requires low privileges, network access, and human interaction. The attack surface includes sandboxed Java Web Start applications, sandboxed Java applets, and API-driven input to the affected component. [truncated]
CVE-2017-3251 describes a MySQL Server vulnerability in Oracle’s Optimizer subcomponent that can let a high-privileged attacker reachable over the network trigger a hang or repeatable crash of the server. The impact is availability-only, but the issue is operationally important because it can produce a complete denial of service on affected MySQL deployments.
CVE-2017-3250 is an Oracle GlassFish Server vulnerability in Oracle Fusion Middleware that affects versions 2.1.1, 3.0.1, and 3.1.2. The public record describes it as easily exploitable over HTTP by an unauthenticated network attacker, with possible unauthorized data read/write access and partial denial of service.
CVE-2017-3249 is an Oracle GlassFish Server vulnerability in the Security subcomponent of Oracle Fusion Middleware. Oracle and NVD describe it as easily exploitable over the network via LDAP by an unauthenticated attacker, with impacts that include unauthorized data read, update, insert, or delete access, plus partial denial of service. NVD rates the issue CVSS 3.0 7.3 (HIGH).
CVE-2017-3248 is a critical Oracle WebLogic Server vulnerability in the Core Components subcomponent. Oracle and NVD describe it as easily exploitable by an unauthenticated attacker with network access via T3, with successful exploitation resulting in takeover of the WebLogic Server. The CVSS v3.0 base score is 9.8, reflecting high confidentiality, integrity, and availability impact.
CVE-2017-3247 is a Medium-severity Oracle GlassFish Server issue affecting supported versions 2.1.1, 3.0.1, and 3.1.2. According to the NVD record, an unauthenticated attacker with network access via SMTP can exploit the flaw, but successful attacks require human interaction from someone other than the attacker. The confirmed impact is limited to integrity: unauthorized update, insert, or delete access to [truncated]
CVE-2017-3246 is a vulnerability in Oracle E-Business Suite's Application Object Library, specifically the Patching subcomponent. According to the supplied record, it affects versions 12.1.3, 12.2.3, 12.2.4, 12.2.5, and 12.2.6. A successful attack can let a high-privileged attacker with logon to the infrastructure where the component runs create, delete, modify, or read critical data.
CVE-2017-3245 is a medium-severity information disclosure issue in Oracle FLEXCUBE Direct Banking, specifically the Pre-Login component. According to the CVE record, an unauthenticated attacker with network access via HTTP can exploit the flaw, but successful attacks require human interaction from a different person. The documented impact is unauthorized read access to a subset of accessible data in affec [truncated]
CVE-2017-3242 is a medium-severity Oracle VM Server for SPARC vulnerability in the LDOM Manager subcomponent that can allow a low-privileged attacker with local logon access to cause a hang or repeatable crash, resulting in denial of service. Oracle/NVD indicate affected supported versions 3.2 and 3.4, and successful exploitation requires human interaction from another person.
CVE-2017-3241 is a critical Oracle Java vulnerability in the RMI component that NVD characterizes as a network-reachable, unauthenticated issue with high confidentiality, integrity, and availability impact. Oracle’s affected versions in the record include Java SE 6u131, 7u121, 8u111/8u112, Java SE Embedded 8u111, and JRockit R28.3.12. The key defensive takeaway is that exposure is not limited to applets o [truncated]
CVE-2017-3240 is a low-severity Oracle Database Server issue in the RDBMS Security component affecting Oracle Database Server 12.1.0.2. According to the NVD record, a low-privileged attacker with local logon access on the infrastructure where RDBMS Security executes could compromise that component and obtain unauthorized read access to a subset of RDBMS Security-accessible data. The CVSS v3.0 base score i [truncated]
CVE-2017-3239 is a low-severity information disclosure vulnerability in Oracle GlassFish Server, part of Oracle Fusion Middleware. According to NVD, it affects GlassFish Server 3.0.1 and 3.1.2 and allows a low-privileged attacker with logon access to the infrastructure where the server runs to read a subset of data accessible to the server. The CVE was published on 2017-01-27, and the NVD record cites Ora [truncated]
CVE-2017-3236 is a medium-severity Oracle FLEXCUBE Universal Banking vulnerability affecting multiple supported releases. According to the supplied NVD data, it is network-accessible over HTTP, requires user interaction, and can allow unauthorized data updates, inserts, or deletes in accessible banking data.
CVE-2017-3235 is a low-severity Oracle FLEXCUBE Universal Banking issue affecting multiple 11.x and 12.x releases. Oracle and NVD describe it as easily exploitable with physical access and capable of unauthorized read and data modification on some accessible data. The main defense focus is strict physical-access control and following Oracle remediation guidance for affected deployments.
CVE-2017-3231 is an Oracle Java SE / Java SE Embedded networking flaw that can expose a limited subset of accessible data. Oracle’s description says it is easily exploitable over the network, but it requires user interaction and is primarily relevant to sandboxed Java Web Start applications or applets that load untrusted code. The documented impact is confidentiality-only, with no integrity or availabilit [truncated]
CVE-2016-8330 is an Oracle Solaris kernel vulnerability affecting Solaris 11.3. According to NVD, it is difficult to exploit, requires only network access, and can be reached by unauthenticated attackers via multiple protocols. The observed impact is integrity-only: successful exploitation could allow unauthorized update, insert, or delete access to some Solaris-accessible data. The CVSS v3.0 base score i [truncated]
CVE-2016-8329 is a medium-severity Oracle PeopleSoft Enterprise PeopleTools issue in the Mobile Application Platform subcomponent. According to NVD, the affected supported versions are 8.54 and 8.55. The vulnerability is network reachable over HTTP and can be exploited without authentication, but successful attacks require human interaction. Impact is limited to confidentiality and integrity, with unautho [truncated]
CVE-2016-8328 affects Oracle Java SE 8u112 and is tied to Java Mission Control installation. NVD rates it Low (CVSS 3.7) and describes a network-reachable issue that does not require authentication, but is difficult to exploit and is limited to integrity impact.
CVE-2016-8327 is a MySQL Server replication issue in Oracle’s product line that can lead to denial of service. Oracle and NVD describe it as difficult to exploit, but a high-privileged attacker with network access may be able to force a hang or repeatedly crash the server.
CVE-2016-8325 is a critical Oracle E-Business Suite vulnerability in the One-to-One Fulfillment component (Internal Operations). Oracle and NVD describe it as easily exploitable over HTTP by an unauthenticated network attacker, with potential for unauthorized creation, deletion, or modification of critical data, or unauthorized access to all accessible One-to-One Fulfillment data. NVD rates it CVSS 9.1 (A [truncated]
CVE-2016-8324 is a medium-severity Oracle FLEXCUBE Core Banking vulnerability affecting Oracle Financial Services Applications Core in versions 5.1.0, 5.2.0, and 11.5.0. According to the NVD description, an unauthenticated attacker with network access via HTTP can compromise the component and obtain unauthorized read access to a subset of accessible data. The CVSS v3.0 base score is 5.3, driven by confide [truncated]
CVE-2016-8323 is a medium-severity Oracle FLEXCUBE Core Banking vulnerability affecting supported versions 5.1.0, 5.2.0, and 11.5.0. According to the CVE record, a low-privileged attacker with network access via HTTP could compromise the application and gain unauthorized read access to some data, as well as unauthorized update, insert, or delete access to some accessible data.
CVE-2016-8322 is an information-disclosure issue in Oracle FLEXCUBE Core Banking, part of Oracle Financial Services Applications. According to NVD, the issue was published on 2017-01-27 and affects supported versions 5.1.0, 5.2.0, and 11.5.0. Oracle describes the vulnerability as easily exploitable by a low-privileged attacker with network access via HTTP, with successful exploitation resulting in unautho [truncated]
CVE-2016-8320 affects Oracle FLEXCUBE Enterprise Limits and Collateral Management 12.0.0 and 12.0.2. NVD describes it as an easily exploitable network issue that requires user interaction and can allow unauthorized read, update, insert, or delete access to some accessible data, with possible impact to additional products.
CVE-2016-8319 affects Oracle FLEXCUBE Investor Servicing and is rated CVSS 6.1 (medium). The NVD record describes an unauthenticated network-accessible issue over HTTP that requires user interaction and can lead to unauthorized read and modification of some accessible data.
CVE-2016-8318 is a denial-of-service issue in the MySQL Server encryption-related security component. Oracle and NVD describe it as network-reachable, low-privileged, and capable of causing a hang or repeatable crash in affected MySQL Server versions, with successful exploitation requiring human interaction from someone other than the attacker.
CVE-2016-8317 is an Oracle FLEXCUBE Investor Servicing vulnerability in the Unit Trust subcomponent. Oracle’s description says a low-privileged attacker with network access via HTTP could compromise affected installations, with successful attacks enabling unauthorized creation, deletion, or modification of critical data. NVD assigns CVSS v3.0 5.3 (Medium) and maps the issue to CWE-284 (improper access control).
CVE-2016-8316 is an Oracle FLEXCUBE Investor Servicing improper-authorization issue (CWE-284) affecting supported versions 12.0.1, 12.0.2, 12.0.4, 12.1.0, and 12.3.0. Oracle’s advisory and NVD describe a network-reachable flaw that requires low privileges and human interaction, with potential confidentiality and integrity impact on accessible data.
CVE-2016-8315 is a high-severity Oracle FLEXCUBE Investor Servicing vulnerability affecting versions 12.0.1, 12.0.2, 12.0.4, 12.1.0, and 12.3.0. NVD describes it as an easily exploitable issue reachable over HTTP by a low-privileged attacker, with the potential for unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or all accessible data in the product.
CVE-2016-8314 is a low-severity Oracle FLEXCUBE Core Banking vulnerability that can let a low-privileged attacker with network access over HTTP read a subset of accessible data. The supplied NVD record lists affected versions 5.1.0, 5.2.0, and 11.5.0, and rates the issue CVSS v3.0 3.1 with confidentiality impact only.