CVE-2010-3591
published 2011-01-19CVE-2010-3591: Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect…
PriorityP358critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
11.82%
95.6th percentile
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Internal Operations. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can overwrite or delete arbitrary files via a full pathname in the second argument to the DownloadSingleMessageToFile method in the EMPOP3Lib ActiveX component (empop3.dll).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy PROMOD IV
cisa_ics·2022-09-20·CVSS 9.3
[CRITICAL] Hitachi Energy PROMOD IV
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy PROMOD IV
Last RevisedSeptember 20, 2022
Alert CodeICSA-22-263-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.0
- ATTENTION: Exploitable Remotely
- Vendor: Hitachi Energy
- Equipment: PROMOD IV
- Vulnerability: Improper Access Control
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to delete arbitrary files once the system is compromised.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of PROMOD IV and the PROMOD-Generator, an energy planning, transmission congestion, and price forecasting system
GHSA
GHSA-5rrj-r5cm-jm8g: Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10
ghsa_unreviewed·2022-05-14
CVE-2010-3591 [HIGH] GHSA-5rrj-r5cm-jm8g: Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Internal Operations. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can overwrite or delete arbitrary files via a full pathname in the second argument to the DownloadSingleMessageToFile method in the EMPOP3Lib ActiveX component (empop3.dll).
No detection rules found.
Exploit-DB
Oracle Document Capture - 'empop3.dll' Insecure Methods
exploitdb·2011-01-26·CVSS 9.3
CVE-2010-3591 [CRITICAL] Oracle Document Capture - 'empop3.dll' Insecure Methods
Oracle Document Capture - 'empop3.dll' Insecure Methods
---
Source: http://packetstormsecurity.org/files/view/97868/DSECRG-11-005.txt
ActiveX components contain insecure methods.
Digital Security Research Group [DSecRG] Advisory DSECRG-11-005 (internal #DSECRG-00154)
Application: Oracle Document Capture
Versions Affected: Release 10gR3
Vendor URL: www.oracle.com
Bugs: insecure method, File overwriting, File deleting
Exploits: YES
Reported: 22.03.2010
Vendor response: 31.03.2010
Date of Public Advisory:24.01.2011
CVE-number: CVE-2010-3591
Author: Evdokimov Dmitriy from Digital Security Research Group [DSecRG] (research [at] dsecrg [dot] com)
Description
Oracle Document Capture contains ActiveX components that contains insecure methods in empop3.dll
Details
Oracle Document Captu
Exploit-DB
Oracle Document Capture - Actbar2.ocx Insecure Method
exploitdb·2011-01-26·CVSS 9.3
CVE-2010-3591 [CRITICAL] Oracle Document Capture - Actbar2.ocx Insecure Method
Oracle Document Capture - Actbar2.ocx Insecure Method
---
Source: http://packetstormsecurity.org/files/view/97866/DSECRG-11-004.txt
ActiveX components contain insecure methods.
Digital Security Research Group [DSecRG] Advisory #DSECRG-00153
Application: Oracle Document Capture
Versions Affected: Release 10gR3
Vendor URL: www.oracle.com
Bugs: insecure method, File overwriting
Exploits: YES
Reported: 22.03.2010
Vendor response: 31.03.2010
Date of Public Advisory:24.01.2011
CVE-number: CVE-2010-3591
Author: Evdokimov Dmitriy from Digital Security Research Group [DSecRG] (research [at] dsecrg [dot] com)
Description
Oracle Document Capture contains ActiveX components that contains insecure methods.
Insecure method in Actbar2.ocx
Details
Oracle Document Capture contains ActiveX comp
No writeups or analysis indexed.
http://dsecrg.com/pages/vul/show.php?id=305http://secunia.com/advisories/42976http://www.exploit-db.com/exploits/16055http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.htmlhttp://www.securityfocus.com/archive/1/515959/100/0/threadedhttp://www.securityfocus.com/bid/45851http://www.securitytracker.com/id?1024981http://www.vupen.com/english/advisories/2011/0143https://exchange.xforce.ibmcloud.com/vulnerabilities/64768http://dsecrg.com/pages/vul/show.php?id=305http://secunia.com/advisories/42976http://www.exploit-db.com/exploits/16055http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.htmlhttp://www.securityfocus.com/archive/1/515959/100/0/threadedhttp://www.securityfocus.com/bid/45851http://www.securitytracker.com/id?1024981http://www.vupen.com/english/advisories/2011/0143https://exchange.xforce.ibmcloud.com/vulnerabilities/64768
2011-01-19
Published