CVE-2016-3514
medium
CVSS v3
6.5
CVSS v2
6.8
VIR risk
6.5
Description
Unspecified vulnerability in the Oracle Enterprise Communications Broker component in Oracle Communications Applications before PCz 2.0.0m4p1 allows remote authenticated users to affect confidentiality via vectors related to GUI, a different vulnerability than CVE-2016-3516.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| oracle | enterprise_communications_broker | {"endIncluding":"2.0.041"} | |
References
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.securityfocus.com/bid/91787
- http://www.securitytracker.com/id/1036401
- http://www.synacktiv.com/ressources/oracle_sbc_configuration_issues.pdf
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.securityfocus.com/bid/91787
- http://www.securitytracker.com/id/1036401
- http://www.synacktiv.com/ressources/oracle_sbc_configuration_issues.pdf
Verify integrity in audit chain (admin only). AS-IS.