CVE-2016-5601Improper Access Control in Oracle Weblogic Server

Severity
6.3MEDIUMNVD
EPSS
0.2%
top 63.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 25
Latest updateMay 14

Description

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows local users to affect confidentiality and integrity via vectors related to CIE Related Components.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:NExploitability: 1.1 | Impact: 4.7

Affected Packages1 packages

NVDoracle/weblogic_server12.1.3.0.0, 12.2.1.0.0, 12.2.1.1.0+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mqxh-rggf-5gq3: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 122022-05-14
CVEList
CVE-2016-5601: Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 122016-10-25
CVE-2016-5601 — Improper Access Control in Oracle | cvebase