CVE-2016-5456
published 2016-07-21CVE-2016-5456: Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote…
PriorityP429medium5.3CVSS 3.0
AVNACHPRLUINSUCHINAN
EPSS
2.13%
79.8th percentile
Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Services.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | siebel_core-server_framework | — | — |
| oracle | siebel_core-server_framework | — | — |
| oracle | siebel_core-server_framework | — | — |
| oracle | siebel_core-server_framework | — | — |
| oracle | siebel_core-server_framework | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.06.3MEDIUMAV:N/AC:M/Au:S/C:C/I:N/A:N
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x6q9-rj9h-c62x: Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8
ghsa_unreviewed·2022-05-17
CVE-2016-5456 [MEDIUM] GHSA-x6q9-rj9h-c62x: Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8
Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Services.
Red Hat
JDK: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix
vendor_redhat·2016-04-14·CVSS 9.3
CVE-2016-0376 [CRITICAL] JDK: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix
JDK: insecure deserialization in CORBA, incorrect CVE-2013-5456 fix
The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block, which allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code as demonstrated by the readValue method of the com.ibm.rmi.io.ValueHandlerPool.ValueHandlerSingleton class, which implements the javax.rmi.CORBA.ValueHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-5456.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/bid/91787http://www.securityfocus.com/bid/91958http://www.securitytracker.com/id/1036400http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.securityfocus.com/bid/91787http://www.securityfocus.com/bid/91958http://www.securitytracker.com/id/1036400
2016-07-21
Published