CVE-2016-0697
published 2016-04-21CVE-2016-0697: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows local users…
PriorityP424medium6CVSS 3.0
AVLACLPRHUINSUCHIHAN
EPSS
0.74%
50.9th percentile
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows local users to affect confidentiality and integrity via unknown vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_object_library | — | — |
| oracle | application_object_library | — | — |
| oracle | application_object_library | — | — |
| oracle | application_object_library | — | — |
CVSS provenance
nvdv3.06.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
nvdv2.03.6LOWAV:N/AC:H/Au:S/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update April 2016 | Qualys
blogs_qualys·2016-04-22·CVSS 8.1
CVE-2016-0636 [HIGH] Oracle Critical Patch Update April 2016 | Qualys
This week Oracle released their quarterly Critical Patch Update (CPU) for April 2016. The CPU addresses 136 vulnerabilities in 49 products, including Java, Solaris, several middleware products, VirtualBox, the MySQL database and the original Oracle database.
Oracle does not mention any vulnerabilities that are under known attacks, but points out that there was an out-of-band release for Java to fix CVE-2016-0636 last month.
Java is one of the software packages that are constantly under attack. Java as a full fledged programming languages gives the attacker a large attack surface and then a wide array of tools to continue post-exploitation. This update fixes nine vulnerabilities with the most three most critical sporting a CVSS of 9.6. The top three apply only to client deployments of Jav
Qualys
Oracle Critical Patch Update April 2016 | Qualys
blogs_qualys·2016-04-22·CVSS 8.1
CVE-2016-0636 [HIGH] Oracle Critical Patch Update April 2016 | Qualys
This week Oracle released their quarterly Critical Patch Update (CPU) for April 2016. The CPU addresses 136 vulnerabilities in 49 products, including Java, Solaris, several middleware products, VirtualBox, the MySQL database and the original Oracle database.
Oracle does not mention any vulnerabilities that are under known attacks, but points out that there was an out-of-band release for Java to fix CVE-2016-0636 last month.
Java is one of the software packages that are constantly under attack. Java as a full fledged programming languages gives the attacker a large attack surface and then a wide array of tools to continue post-exploitation. This update fixes nine vulnerabilities with the most three most critical sporting a CVSS of 9.6. The top three apply only to client deployments of Jav
2016-04-21
Published