CVE-2015-1926
published 2015-07-16CVE-2015-1926: Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 and 11.1.1.9.0, and the Oracle Applications Framework…
PriorityP426medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
1.76%
75.7th percentile
Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 and 11.1.1.9.0, and the Oracle Applications Framework component in Oracle E-Business Suite 12.2.3 and 12.2.4, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Portal.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fp36-f4xw-x2j7: Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11
ghsa_unreviewed·2022-05-17
CVE-2015-1926 [MEDIUM] GHSA-fp36-f4xw-x2j7: Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11
Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 and 11.1.1.9.0, and the Oracle Applications Framework component in Oracle E-Business Suite 12.2.3 and 12.2.4, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Portal.
Red Hat
spec: Information disclosure via missing access restriction in resource dispatching
vendor_redhat·2015-07-30·CVSS 5.5
CVE-2015-1926 [MEDIUM] spec: Information disclosure via missing access restriction in resource dispatching
spec: Information disclosure via missing access restriction in resource dispatching
Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.8.0 and 11.1.1.9.0, and the Oracle Applications Framework component in Oracle E-Business Suite 12.2.3 and 12.2.4, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Portal.
The Java Portlet Specification JSR286 API jar file code could allow a remote attacker to obtain sensitive information, caused by the failure to restrict access to resources located within the web application. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.
Statement: CVE-2015-1926 did not affect JBoss Portal Platform as pro
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-4908 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
bugzilla·2015-10-21·CVSS 5.0
CVE-2015-4908 [MEDIUM] CVE-2015-4908 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
CVE-2015-4908 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
Oracle Java SE 8u65 fixes an unspecified vulnerability in the JavaFX component (CVE-2015-4908). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 6
Via RHSA-2015:1926 https://rhn.redhat.com/errata/RHSA-2015-1926.html
Bugzilla
CVE-2015-4901 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
bugzilla·2015-10-21·CVSS 9.3
CVE-2015-4901 [CRITICAL] CVE-2015-4901 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
CVE-2015-4901 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
Oracle Java SE 8u65 fixes an unspecified vulnerability in the JavaFX component (CVE-2015-4901). Upstream has CVSSv2 scored this issue as: 9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 6
Via RHSA-2015:1926 https://rhn.redhat.com/errata/RHSA-2015-1926.html
Bugzilla
CVE-2015-4906 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
bugzilla·2015-10-21·CVSS 5.0
CVE-2015-4906 [MEDIUM] CVE-2015-4906 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
CVE-2015-4906 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
Oracle Java SE 8u65 fixes an unspecified vulnerability in the JavaFX component (CVE-2015-4906). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 6
Via RHSA-2015:1926 https://rhn.redhat.com/errata/RHSA-2015-1926.html
Bugzilla
CVE-2015-4916 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
bugzilla·2015-10-21·CVSS 5.0
CVE-2015-4916 [MEDIUM] CVE-2015-4916 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
CVE-2015-4916 Oracle JDK: unspecified vulnerability fixed in 8u65 (JavaFX)
Oracle Java SE 8u65 fixes an unspecified vulnerability in the JavaFX component (CVE-2015-4916). Upstream has CVSSv2 scored this issue as: 5.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 6
Via RHSA-2015:1926 https://rhn.redhat.com/errata/RHSA-2015-1926.html
Bugzilla
CVE-2015-4810 Oracle JDK: unspecified vulnerability fixed in 7u91 and 8u65 (Deployment)
bugzilla·2015-10-21·CVSS 6.9
CVE-2015-4810 [MEDIUM] CVE-2015-4810 Oracle JDK: unspecified vulnerability fixed in 7u91 and 8u65 (Deployment)
CVE-2015-4810 Oracle JDK: unspecified vulnerability fixed in 7u91 and 8u65 (Deployment)
Oracle Java SE 7u91 and 8u65 fixes an unspecified vulnerability in the Deployment component (CVE-2015-4810). Upstream has CVSSv2 scored this issue as: 6.9/AV:L/AC:M/Au:N/C:C/I:C/A:C
External Reference:
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixJAVA
Discussion:
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 6
Via RHSA-2015:1926 https://rhn.redhat.com/errata/RHSA-2015-1926.html
---
This issue has been addressed in the following products:
Oracle Java for Red Hat Enterprise Linux 7
Oracle Java for Red Hat Enterprise Linux 5
Oracle Java for Red Hat Enterprise Linux 6
Bugzilla
CVE-2015-1926 Portlet spec: Information disclosure via missing access restriction in resource dispatching
bugzilla·2015-04-17·CVSS 5.5
CVE-2015-1926 [MEDIUM] CVE-2015-1926 Portlet spec: Information disclosure via missing access restriction in resource dispatching
CVE-2015-1926 Portlet spec: Information disclosure via missing access restriction in resource dispatching
The Java Portlet Specification JSR286 API jar file code could
allow a remote attacker to obtain sensitive information, caused by the
failure to restrict access to resources located within the web application.
An attacker could exploit this vulnerability to obtain configuration data
and other sensitive information.
Problem summary:
A resource ID string can be set on a resource URL. If a resource ID is
present, the default behavior of the GenericPortlet#serveResource method is
to dispatch to the resource identified by the resource ID through a request
dispatcher. The vulnerability can occur if an attacker manipulates the
resource ID field on a resource URL to point to a resource such
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/75860http://www.securitytracker.com/id/1032926http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlhttp://www.securityfocus.com/bid/75860http://www.securitytracker.com/id/1032926
2015-07-16
Published