CVE-2012-3506
published 2012-10-25CVE-2012-3506: Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
PriorityP341critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
7.48%
93.8th percentile
Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
| apache | ofbiz | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_apache10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
vendor_redhat·2012-01-18·CVSS 4.3
CVE-2012-0079 [MEDIUM] OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
Unspecified vulnerability in Oracle OpenSSO 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Administration.
Statement: Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quickstart has been removed in JBoss Enterprise SOA Platform 5.3.0 to address these flaws. Users interested in continuing to
Red Hat
OpenSSO: unspecified vulnerability in the authentication component
vendor_redhat·2011-10-18·CVSS 4.3
CVE-2011-3517 [MEDIUM] OpenSSO: unspecified vulnerability in the authentication component
OpenSSO: unspecified vulnerability in the authentication component
Unspecified vulnerability in the Oracle OpenSSO component in Oracle Sun Products Suite 8.0 allows remote attackers to affect availability via unknown vectors related to Authentication.
Statement: Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quickstart has been removed in JBoss Enterprise SOA Platform 5.3.0 to address these flaws. Users interested in continui
Red Hat
OpenSSO: unspecified vulnerability in the authentication component
vendor_redhat·2011-10-18·CVSS 4.3
CVE-2011-3506 [MEDIUM] OpenSSO: unspecified vulnerability in the authentication component
OpenSSO: unspecified vulnerability in the authentication component
Unspecified vulnerability in the Oracle OpenSSO component in Oracle Sun Products Suite 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Authentication.
Statement: Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quickstart has been removed in JBoss Enterprise SOA Platform 5.3.0 to address these flaws. Users interested in con
Apache
Apache ofbiz: CVE-2012-3506
vendor_apache·CVSS 10.0
CVE-2012-3506 [CRITICAL] Apache ofbiz: CVE-2012-3506
Apache ofbiz: CVE-2012-3506
; affected releases: 10.04.02, 10.04 (10.04.01); fixed in 10.04.03
GHSA
GHSA-c9qh-45f6-r2vv: Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10
ghsa_unreviewed·2022-05-14
CVE-2012-3506 [HIGH] GHSA-c9qh-45f6-r2vv: Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10
Unspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0079 OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
bugzilla·2012-01-23·CVSS 4.3
CVE-2012-0079 [MEDIUM] CVE-2012-0079 OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
CVE-2012-0079 OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-0079 to the following vulnerability:
Unspecified vulnerability in Oracle OpenSSO 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Administration.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0079
Discussion:
Statement:
Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application i
Bugzilla
CVE-2011-3517 Oracle OpenSSO: unspecified vulnerability in the authentication component
bugzilla·2011-10-26·CVSS 4.3
CVE-2011-3517 [MEDIUM] CVE-2011-3517 Oracle OpenSSO: unspecified vulnerability in the authentication component
CVE-2011-3517 Oracle OpenSSO: unspecified vulnerability in the authentication component
Oracle OpenSSO 8.0 exposes an unspecified vulnerability in the authentication component, allowing a remote attacker to perform a denial of service (CVE-2011-3517).
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html
---
Statement:
Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso qui
Bugzilla
CVE-2011-3506 Oracle OpenSSO: unspecified vulnerability in the authentication component
bugzilla·2011-10-26·CVSS 4.3
CVE-2011-3506 [MEDIUM] CVE-2011-3506 Oracle OpenSSO: unspecified vulnerability in the authentication component
CVE-2011-3506 Oracle OpenSSO: unspecified vulnerability in the authentication component
Oracle OpenSSO 7.1 and 8.0 expose an unspecified vulnerability in the authentication component, allowing attackers to manipulate certain data (CVE-2011-3506).
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html
---
Statement:
Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quicksta
http://ofbiz.apache.org/download.html#vulnerabilitieshttp://osvdb.org/86556http://seclists.org/fulldisclosure/2012/Oct/156http://www.securityfocus.com/bid/56171https://exchange.xforce.ibmcloud.com/vulnerabilities/79540http://ofbiz.apache.org/download.html#vulnerabilitieshttp://osvdb.org/86556http://seclists.org/fulldisclosure/2012/Oct/156http://www.securityfocus.com/bid/56171https://exchange.xforce.ibmcloud.com/vulnerabilities/79540
2012-10-25
Published