CVE-2013-0376
published 2013-01-17CVE-2013-0376: Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.98%
58.7th percentile
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Diagnostics.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r2w5-qg4h-qjvv: Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11
ghsa_unreviewed·2022-05-05
CVE-2013-0376 [MEDIUM] GHSA-r2w5-qg4h-qjvv: Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Diagnostics.
Red Hat
JDK: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix
vendor_redhat·2016-04-14·CVSS 9.3
CVE-2016-0376 [CRITICAL] JDK: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix
JDK: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix
The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-01-17
Published