CVE-2015-0402
published 2015-01-21CVE-2015-0402: Unspecified vulnerability in the Siebel Core - Server BizLogic Script component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.22%
65.4th percentile
Unspecified vulnerability in the Siebel Core - Server BizLogic Script component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via vectors related to Integration - COM.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | siebel_crm | — | — |
| oracle | siebel_crm | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3qc6-cvgf-f4r6: Unspecified vulnerability in the Siebel Core - Server BizLogic Script component in Oracle Siebel CRM 8
ghsa_unreviewed·2022-05-17
CVE-2015-0402 [MEDIUM] GHSA-3qc6-cvgf-f4r6: Unspecified vulnerability in the Siebel Core - Server BizLogic Script component in Oracle Siebel CRM 8
Unspecified vulnerability in the Siebel Core - Server BizLogic Script component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via vectors related to Integration - COM.
OSV
openjdk-7 vulnerabilities
osv·2016-02-01·CVSS 5.9
CVE-2016-0483 openjdk-7 vulnerabilities
openjdk-7 vulnerabilities
Multiple vulnerabilities were discovered in the OpenJDK JRE related
to information disclosure, data integrity, and availability. An
attacker could exploit these to cause a denial of service, expose
sensitive data over the network, or possibly execute arbitrary code.
(CVE-2016-0483, CVE-2016-0494)
A vulnerability was discovered in the OpenJDK JRE related to data
integrity. An attacker could exploit this to expose sensitive data
over the network or possibly execute arbitrary code. (CVE-2016-0402)
It was discovered that OpenJDK 7 incorrectly allowed MD5 to be used
for TLS connections. If a remote attacker were able to perform a
machine-in-the-middle attack, this flaw could be exploited to expose
sensitive information. (CVE-2015-7575)
A vulnerability was discovere
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.securityfocus.com/bid/72187http://www.securitytracker.com/id/1031578https://exchange.xforce.ibmcloud.com/vulnerabilities/100121http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.htmlhttp://www.securityfocus.com/bid/72187http://www.securitytracker.com/id/1031578https://exchange.xforce.ibmcloud.com/vulnerabilities/100121
2015-01-21
Published