PatchSiren

Oracle CVE debriefs · Page 26

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8313

CVE-2016-8313 is a medium-severity Oracle FLEXCUBE Private Banking issue affecting the Product / Instrument Search subcomponent. According to Oracle and NVD, a low-privileged attacker with network access over HTTP could trigger the flaw with human interaction from another person and obtain unauthorized read access to a subset of accessible data. The issue was published on 2017-01-27 and is rated CVSS 4.1 [truncated]

HIGH Oracle CVE published 2017-01-27

CVE-2016-8312

CVE-2016-8312 affects Oracle FLEXCUBE Private Banking in supported versions 2.0.1, 2.2.0, and 12.0.1. According to the CVE record, the issue is network reachable over HTTP, requires no attacker authentication, but does require human interaction, and can lead to unauthorized access to critical data or modification of accessible data. Oracle’s January 2017 CPU is referenced by NVD as the vendor advisory/pat [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8311

CVE-2016-8311 is a medium-severity Oracle FLEXCUBE Universal Banking vulnerability affecting the Core component in several supported releases. Oracle and NVD describe it as an easily exploitable issue reachable over HTTP by a low-privileged network attacker, with the main impact being unauthorized access to sensitive data.

HIGH Oracle CVE published 2017-01-27

CVE-2016-8310

CVE-2016-8310 affects Oracle FLEXCUBE Universal Banking and is described by NVD as a network-exploitable, unauthenticated issue reachable over HTTP. Oracle and NVD list supported affected versions across several FLEXCUBE releases, and the impact includes unauthorized read and write access to some data plus partial denial of service. The CVSS v3.0 base score is 7.3, which makes this a high-priority remedia [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8309

CVE-2016-8309 is a medium-severity access control issue in Oracle FLEXCUBE Investor Servicing Core. Oracle and NVD state that a low-privileged attacker with network access via HTTP could gain unauthorized read access to a subset of accessible data in affected releases.

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8308

CVE-2016-8308 is a medium-severity Oracle FLEXCUBE Private Banking vulnerability affecting the Product / Instrument Search subcomponent. Oracle and NVD describe it as remotely reachable over HTTP, requiring human interaction, and capable of unauthorized data updates, inserts, or deletions in accessible FLEXCUBE Private Banking data.

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8307

CVE-2016-8307 affects Oracle FLEXCUBE Universal Banking and is described as an easily exploitable, unauthenticated network-accessible issue over HTTP that can lead to unauthorized read access to a subset of accessible data. Oracle and NVD list affected releases including 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, and 12.2.0. Public disclosure is dated 2017-01-27.

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8306

CVE-2016-8306 affects Oracle FLEXCUBE Investor Servicing (Core) and was published by NVD on 2017-01-27. Oracle’s advisory and the NVD entry describe an easily exploitable issue reachable over HTTP by a low-privileged attacker. Successful exploitation can allow unauthorized read access to some accessible data and unauthorized insert, update, or delete access to some accessible data. The NVD record assigns [truncated]

LOW Oracle CVE published 2017-01-27

CVE-2016-8305

CVE-2016-8305 is a low-severity information disclosure issue affecting Oracle FLEXCUBE Universal Banking. According to the NVD record, exploitation requires physical access and user interaction by someone other than the attacker, and successful attacks can expose a subset of accessible data. The issue is listed against multiple FLEXCUBE Universal Banking versions and maps to CWE-200.

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8304

CVE-2016-8304 is a medium-severity Oracle FLEXCUBE Universal Banking issue affecting multiple supported releases. According to NVD, a low-privileged network attacker can exploit the flaw over HTTP, but success requires human interaction and can lead to unauthorized data reads and updates within FLEXCUBE.

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8303

CVE-2016-8303 affects Oracle FLEXCUBE Universal Banking Core in supported versions 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, and 12.2.0. NVD rates the issue CVSS v3.0 6.1 (Medium) with network access, no privileges required, but user interaction required. Successful exploitation can expose some accessible data to unauthorized read access and enable unauthorized data modification, and the record note [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8302

CVE-2016-8302 is an Oracle FLEXCUBE Universal Banking information-disclosure issue affecting multiple supported releases. Oracle and NVD describe a low-privileged, network-accessible HTTP attack path that can expose a subset of accessible data, with no integrity or availability impact listed.

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8301

CVE-2016-8301 affects Oracle FLEXCUBE Universal Banking Core and was published by NVD on 2017-01-27. Oracle’s affected versions listed in the record include 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, and 12.2.0. The issue is network reachable over HTTP, requires no attacker authentication, but does require human interaction by another person. The documented impact is limited to integrity: unauthorize [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8300

CVE-2016-8300 is a network-reachable access-control vulnerability in Oracle FLEXCUBE Private Banking’s Product / Instrument Search component. Oracle and NVD list affected versions 2.0.1, 2.2.0, and 12.0.1. The issue is rated CVSS 3.0 5.3 (Medium) with high confidentiality impact, meaning a low-privileged attacker who can reach the application over HTTP may be able to access sensitive banking data without [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8299

CVE-2016-8299 is a medium-severity vulnerability in Oracle FLEXCUBE Universal Banking that was publicly recorded on 2017-01-27. According to NVD, it is an easily exploitable issue reachable over HTTP by a low-privileged attacker, and successful exploitation can lead to unauthorized read, insert, update, or delete access to some accessible data, along with partial denial of service.

HIGH Oracle CVE published 2017-01-27

CVE-2016-8298

CVE-2016-8298 is a high-severity Oracle FLEXCUBE Private Banking vulnerability in the Product / Instrument Search subcomponent. NVD rates it CVSS 3.0 8.1 and describes it as easily exploitable by a low-privileged attacker with network access over HTTP, with impact to confidentiality and integrity.

HIGH Oracle CVE published 2017-01-27

CVE-2016-8297

CVE-2016-8297 is a high-severity Oracle FLEXCUBE Universal Banking vulnerability in the Core subcomponent. According to the NVD record and Oracle’s referenced CPU advisory, a low-privileged attacker with network access via HTTP can compromise affected deployments, with primary impact to confidentiality and integrity. The issue affects multiple supported versions and is classified by NVD under CWE-284 (imp [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-8282

CVE-2016-8282 is a medium-severity Oracle FLEXCUBE Private Banking issue affecting the Product / Instrument Search component. According to the official description, an unauthenticated attacker with network access via HTTP can compromise affected deployments, but successful attacks require human interaction by someone other than the attacker. Oracle states the issue can lead to unauthorized read access to [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-5623

CVE-2016-5623 is a medium-severity Oracle FLEXCUBE Private Banking issue affecting the Product / Instrument Search subcomponent. Oracle and NVD describe it as an easily exploitable weakness reachable over HTTP by a low-privileged network attacker, with impact limited to confidentiality and integrity of some accessible data. Affected supported versions include 2.0.1, 2.2.0, and 12.0.1.

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-5614

CVE-2016-5614 is an information disclosure vulnerability in Oracle FLEXCUBE Private Banking’s Product / Instrument Search component. Oracle states that a low-privileged attacker with network access via HTTP could use the flaw to obtain unauthorized read access to a subset of accessible data in affected releases.

HIGH Oracle CVE published 2017-01-27

CVE-2016-5590

CVE-2016-5590 affects the Monitoring: Agent subcomponent of Oracle MySQL Enterprise Monitor. According to NVD, a high-privileged attacker with network access via TLS could compromise the product, with potential takeover of MySQL Enterprise Monitor. Oracle’s cited advisory and NVD indicate affected supported versions include 3.1.3.7856 and earlier.

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-5552

CVE-2016-5552 is a medium-severity Oracle Java vulnerability first published on 2017-01-27. NVD describes it as an easily exploitable, network-accessible flaw in the Java SE networking component that can affect Java SE, Java SE Embedded, and JRockit. The stated impact is unauthorized update, insert, or delete access to some accessible data, with integrity impact rather than confidentiality or availability [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-5549

CVE-2016-5549 is a Java libraries vulnerability in Oracle Java SE and Java SE Embedded that affects sandboxed client deployments running untrusted code. Oracle/NVD describe it as network-exploitable, but successful exploitation requires human interaction. The main risk is confidentiality exposure in Java client environments such as Java Web Start applications and Java applets; typical trusted-code server [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-5548

CVE-2016-5548 is a Java SE / Java SE Embedded vulnerability in the Libraries subcomponent that Oracle rates as easily exploitable over the network, but it requires human interaction and affects sandboxed client-style Java deployments more than trusted server deployments. In the affected versions, a successful attack can lead to unauthorized access to critical data or to all Java-accessible data, with conf [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-5547

CVE-2016-5547 is a network-exploitable Oracle Java vulnerability in the Libraries component affecting specific Java SE, Java SE Embedded, and JRockit releases. Oracle and NVD describe the impact as partial denial of service only, with exposure possible in both client and server deployments, including sandboxed Java Web Start applications, sandboxed Java applets, and API-driven data handling.

HIGH Oracle CVE published 2017-01-27

CVE-2016-5546

CVE-2016-5546 is a network-exploitable Oracle Java libraries vulnerability affecting specified Java SE, Java SE Embedded, and JRockit releases. Oracle/NVD describe unauthenticated access over multiple protocols, with impact focused on unauthorized data creation, deletion, or modification. The issue applies to client and server deployments and can be reached through sandboxed Java Web Start applications, s [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-5545

CVE-2016-5545 is a medium-severity Oracle VM VirtualBox GUI vulnerability affecting VirtualBox prior to 5.0.32 and prior to 5.1.14. According to the CVE record, an unauthenticated network attacker can trigger the issue over HTTP, but successful exploitation requires human interaction from someone other than the attacker. The documented impact is limited to subset data exposure, data modification, and part [truncated]

MEDIUM Oracle CVE published 2017-01-27

CVE-2016-5541

CVE-2016-5541 affects the MySQL Cluster component of Oracle MySQL, specifically the Cluster: NDBAPI subcomponent. Oracle and NVD identify affected releases as 7.2.26 and earlier, 7.3.14 and earlier, and 7.4.12 and earlier. A remote unauthenticated attacker with network access can, with difficult exploitation conditions, potentially perform unauthorized data updates, inserts, or deletes, or cause a partial [truncated]

CRITICAL Oracle CVE published 2017-01-27

CVE-2016-5528

CVE-2016-5528 is a critical Oracle GlassFish Server vulnerability in the Security subcomponent that can allow an unauthenticated attacker with network access via multiple protocols to compromise the server. Oracle and NVD describe successful attacks as potentially resulting in takeover of Oracle GlassFish Server, with high confidentiality, integrity, and availability impact. The affected supported version [truncated]

LOW Oracle CVE published 2017-01-27

CVE-2016-5509

CVE-2016-5509 is a low-severity information disclosure issue in Oracle FLEXCUBE Investor Servicing. Oracle and NVD describe it as accessible to a low-privileged attacker with network access via HTTP, with successful exploitation resulting in unauthorized read access to a subset of accessible data. The NVD entry maps the issue to specific affected 12.x releases and rates it CVSS 3.0 3.1 (Low).