CVE-2013-5763
published 2013-12-12CVE-2013-5763: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 allows context-dependent attackers to affect…
PriorityP47low1.5CVSS 2.0
AVLACMAuSCNINAP
EPSS
0.47%
38.1th percentile
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Maintenance. NOTE: the original disclosure of this issue erroneously mapped it to CVE-2013-3624.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| baramundi | management_suite | — | — |
| baramundi | management_suite | — | — |
| baramundi | management_suite | — | — |
| baramundi | management_suite | — | — |
| baramundi | management_suite | — | — |
| baramundi | management_suite | — | — |
| baramundi | management_suite | — | — |
| baramundi | management_suite | — | — |
| baramundi | management_suite | — | — |
| baramundi | management_suite | — | — |
| baramundi | management_suite | — | — |
| oracle | fusion_middleware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-938h-r443-c3jh: The OS deployment feature in Baramundi Management Suite 7
ghsa_unreviewed·2022-05-17·CVSS 1.5
CVE-2013-3624 [LOW] GHSA-938h-r443-c3jh: The OS deployment feature in Baramundi Management Suite 7
The OS deployment feature in Baramundi Management Suite 7.5 through 8.9 stores credentials in cleartext on deployed machines, which allows remote attackers to obtain sensitive information by reading a file. NOTE: this ID was also incorrectly mapped to a separate issue in Oracle Outside In, but the correct ID for that issue is CVE-2013-5763.
GHSA
GHSA-xqrv-vpmx-2rm7: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8
ghsa_unreviewed·2022-05-14·CVSS 7.8
CVE-2013-5763 [HIGH] GHSA-xqrv-vpmx-2rm7: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Maintenance. NOTE: the original disclosure of this issue erroneously mapped it to CVE-2013-3624.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Update Tuesday: December 2013, some 0-day fixes
blogs_talos·2013-12-10·CVSS 5.5
CVE-2013-5045 [MEDIUM] Microsoft Update Tuesday: December 2013, some 0-day fixes
## Microsoft Update Tuesday: December 2013, some 0-day fixes
Microsoft’s final update for the year brings us 11 bulletins covering 24 CVE issues.
As is customary, there is the critical IE bulletin, MS13-097 . This time it covers 7 CVE issues. As in other months, this includes a number of use-after-free issues that we’ve come to expect in IE. However this month we also get 2 escalation of privilege vulnerabilities ( CVE-2013-5045 and CVE-2013-5046 ), where an attacker could break out of the low integrity sandbox. This assumes of course that the attacker has first gained remote code execution through another vulnerability and then uses one of these vulnerabilities to execute arbitrary programs.
There is also a critical update for GDI+, MS13-096 . This one fixes the 0-day vulnerability ( C
Talos
Microsoft Update Tuesday: December 2013, some 0-day fixes
blogs_talos·2013-12-10·CVSS 5.5
CVE-2013-5045 [MEDIUM] Microsoft Update Tuesday: December 2013, some 0-day fixes
Microsoft’s final update for the year brings us 11 bulletins covering 24 CVE issues.
As is customary, there is the critical IE bulletin, MS13-097. This time it covers 7 CVE issues. As in other months, this includes a number of use-after-free issues that we’ve come to expect in IE. However this month we also get 2 escalation of privilege vulnerabilities (CVE-2013-5045 and CVE-2013-5046), where an attacker could break out of the low integrity sandbox. This assumes of course that the attacker has first gained remote code execution through another vulnerability and then uses one of these vulnerabilities to execute arbitrary programs.
There is also a critical update for GDI+, MS13-096. This one fixes the 0-day vulnerability (CVE-2013-3906) that is being exploited in the wild. The vulnerabilit
http://secunia.com/advisories/56237http://secunia.com/advisories/56241http://secunia.com/advisories/56243http://www-01.ibm.com/support/docview.wss?uid=swg21660640http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.htmlhttp://www.securityfocus.com/bid/63741http://www.securitytracker.com/id/1029190https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-105http://secunia.com/advisories/56237http://secunia.com/advisories/56241http://secunia.com/advisories/56243http://www-01.ibm.com/support/docview.wss?uid=swg21660640http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.htmlhttp://www.securityfocus.com/bid/63741http://www.securitytracker.com/id/1029190https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-105
2013-12-12
Published