CVE-2013-1533
published 2013-04-17CVE-2013-1533: Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 3.1.0, 5.1.0, 5.2.0, 5.3.1…
PriorityP424medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
0.95%
57.1th percentile
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 3.1.0, 5.1.0, 5.2.0, 5.3.1 through 5.3.3, and 6.0.1 through 12.0.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to BASE.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
| oracle | financial_services_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection
suricata·2013-06-13
CVE-2012-1533 ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection
ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible 2012-1533 altjvm RCE via JNLP command injection"; flow:established,to_client; file.data; content:"<jnlp"; nocase; content:"initial-heap-size"; nocase; content:"max-heap-size"; content:"-XXaltjvm"; nocase; fast_pattern; reference:cve,2012-1533; classtype:trojan-activity; sid:2017013; rev:4; metadata:created_at 2013_06_13, cve CVE_2012_1533, confidence Medium, signature_severity Major, updated_at 2024_03_13, mitre_tactic_id TA0008, mitre_tactic_name Lateral_Movement, mitre_technique_id T1210, mitre_technique_name Exploitation_Of_Remote_Services;)
No writeups or analysis indexed.
2013-04-17
Published