CVE-2013-1495

medium
Published 2013-03-18 · Modified 2026-04-29
CVSS v3
CVSS v2
6.9
VIR risk
6.9

Description

asr in Oracle Auto Service Request in Oracle Support Tools before 4.3.2 allows local users to modify arbitrary files via a symlink attack on a predictable filename in /tmp.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html

Application impact

VendorProductVersionsFixed
oraclesupport_tools{"endIncluding":"4.3.2"}

References

CWEs

CWE-59

Verify integrity in audit chain (admin only). AS-IS.