CVE-2012-0544
published 2012-05-03CVE-2012-0544: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through…
PriorityP413low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.19%
64.2th percentile
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect integrity via unknown vectors related to Core, a different vulnerability than CVE-2012-0571.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6cfr-89cj-jf9q: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10
ghsa_unreviewed·2022-05-04·CVSS 4.0
CVE-2012-0544 [MEDIUM] GHSA-6cfr-89cj-jf9q: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect integrity via unknown vectors related to Core, a different vulnerability than CVE-2012-0571.
GHSA
GHSA-7w39-2c97-4p7p: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10
ghsa_unreviewed·2022-05-04·CVSS 3.5
CVE-2012-0571 [LOW] GHSA-7w39-2c97-4p7p: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0 through 10.5.0 and 11.0.0 through 11.4.0 allows remote authenticated users to affect integrity via unknown vectors related to Core, a different vulnerability than CVE-2012-0544.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
bugzilla·2012-11-30·CVSS 4.3
CVE-2012-5604 [MEDIUM] CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
CVE-2012-5604 rubygem-ldap_fluff: CloudForms authentication bypass when handling anonymous LDAP bind
Og Maciel of Red Hat reports:
After configuring my system to use ActiveDirectory as the authentication
method, I was able to login via the web ui without having to provide a
password when using Windows ADS as the LDAP authentication backend.
Discussion:
Acknowledgements:
This issue was discovered by Og Maciel of Red Hat.
---
This issue did not affect CloudForms 1.0, which did not include this component. The issue is fixed in CloudFroms 1.1. No released version of CloudFroms was affected by this issue.
---
This issue has been addressed in following products:
Red Hat Subscription Asset Manager 1.2
Via RHSA-2013:0544 https://rhn.redhat.com/errata/RHSA-2013-0544.html
Bugzilla
CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
bugzilla·2012-11-30·CVSS 5.5
CVE-2012-5603 [MEDIUM] CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
CVE-2012-5603 CloudForms Katello: lack of authorization in proxies_controller.rb
Lukas Zapletal of Red Hat reports:
Regular user (somebody with username and password) and a consumer UUID of any
system can download the consumer certificate and consume content or modify
data without permission to do that.
Discussion:
Acknowledgements:
This issue was discovered by Lukas Zapletal of Red Hat.
---
This issue has been addressed in following products:
CloudForms for RHEL 6
CloudForms Tools for RHEL 5
Via RHSA-2012:1543 https://rhn.redhat.com/errata/RHSA-2012-1543.html
---
This issue has been addressed in following products:
Red Hat Subscription Asset Manager 1.2
Via RHSA-2013:0544 https://rhn.redhat.com/errata/RHSA-2013-0544.html
---
The Red Hat Security Response Team has rated this
http://secunia.com/advisories/48831http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.securityfocus.com/bid/53106http://www.securitytracker.com/id?1026953http://secunia.com/advisories/48831http://www.mandriva.com/security/advisories?name=MDVSA-2013:150http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlhttp://www.securityfocus.com/bid/53106http://www.securitytracker.com/id?1026953
2012-05-03
Published