CVE-2015-4912
published 2015-10-22CVE-2015-4912: Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2.2 and 11.1.2.3 allows remote attackers to affect…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.67%
74.3th percentile
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2.2 and 11.1.2.3 allows remote attackers to affect confidentiality via vectors related to SSO Engine.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Hawkeye-G 3.0.1.4912 - Persistent Cross-Site Scripting / Information Leakage
exploitdb·2015-07-27
Hawkeye-G 3.0.1.4912 - Persistent Cross-Site Scripting / Information Leakage
Hawkeye-G 3.0.1.4912 - Persistent Cross-Site Scripting / Information Leakage
---
# Exploit Title: Persistent XSS, Information Leakage IDS / IPS
# Google Dork: intitle: Persistent XSS, Information Leakage IDS / IPS
# Date: 2015-07-25
# Exploit Author: John Page ( hyp3rlinx )
# Website: hyp3rlinx.altervista.org
# Vendor Homepage: www.hexiscyber.com
# Software Link: www.hexiscyber.com/products/hawkeye-g
# Version: v3.0.1.4912
# Tested on: windows 7 SP1
# Category: Network Threat Appliance IDS / IPS
Vendor:
www.hexiscyber.com
Product:
Hawkeye-G v3.0.1.4912
Hawkeye G is an active defense disruptive technology that
detects, investigates, remediates and removes cyber threats
within the network.
Vulnerability Type:
Persistent XSS & Server Information Leakage
CVE Reference:
N/A
Advisor
Exploit-DB
Hawkeye-G 3.0.1.4912 - Cross-Site Request Forgery
exploitdb·2015-07-24·CVSS 8.8
CVE-2015-2878 [HIGH] Hawkeye-G 3.0.1.4912 - Cross-Site Request Forgery
Hawkeye-G 3.0.1.4912 - Cross-Site Request Forgery
---
# Exploit Title: CSRF, Network Threat Appliance IDS / IPS
# Google Dork: intitle: CSRF Network Threat Appliance IDS / IPS
# Date: 2015-07-24
# Exploit Author: John Page ( hyp3rlinx )
# Website: hyp3rlinx.altervista.org
# Vendor Homepage: www.hexiscyber.com
# Software Link: www.hexiscyber.com/products/hawkeye-g
# Version: v3.0.1.4912
# Tested on: windows 7 SP1
# Category: Network Threat Appliance IDS / IPS
Vulnerability Type:
CSRF
CVE Reference:
CVE-2015-2878
Vendor:
www.hexiscyber.com
Product:
Hawkeye-G v3.0.1.4912
Hawkeye G is an active defense disruptive technology that detects,
investigates, remediates and removes cyber threats within the network.
Advisory Information:
Multiple CSRF(s) Vulnerabilities:
Vulnerability D
No writeups or analysis indexed.
2015-10-22
Published