CVE-2017-3277
published 2017-01-27CVE-2017-3277: Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: OAM Client). Supported versions that are affected are…
PriorityP426medium4.9CVSS 3.0
AVNACLPRHUINSUCHINAN
EPSS
1.43%
70.0th percentile
Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: OAM Client). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS v3.0 Base Score 4.9 (Confidentiality impacts).
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | applications_manager | — | — |
| oracle | applications_manager | — | — |
| oracle | applications_manager | — | — |
| oracle | applications_manager | — | — |
| oracle | applications_manager | — | — |
CVSS provenance
nvdv3.04.9MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-1000200 tcmu-runner: UnregisterHandler D-Bus method in tcmu-runner daemon for internal handler causes DoS
bugzilla·2017-08-31·CVSS 7.5
CVE-2017-1000200 [HIGH] CVE-2017-1000200 tcmu-runner: UnregisterHandler D-Bus method in tcmu-runner daemon for internal handler causes DoS
CVE-2017-1000200 tcmu-runner: UnregisterHandler D-Bus method in tcmu-runner daemon for internal handler causes DoS
A local non-root user with access to the D-Bus system bus can call the
UnregisterHandler method implemented in the tcmu-runner daemon with the
name of a handler loaded internally in tcmu-runner via dlopen() and
cause a NULL pointer dereference resulting in DoS.
Upstream patch:
https://github.com/open-iscsi/tcmu-runner/commit/bb80e9c7a798f035768260ebdadffb6eb0786178
References:
http://seclists.org/oss-sec/2017/q3/207
Discussion:
Created tcmu-runner tracking bugs for this issue:
Affects: fedora-all [bug 1487255]
---
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.3 for RHEL 7
Via RHSA-2017:3277 https://access.redhat.com/errata/RHSA-
Bugzilla
CVE-2017-1000201 tcmu-runner: UnregisterHandler dbus method in tcmu-runner daemon for non-existing handler causes DoS
bugzilla·2017-08-31·CVSS 5.5
CVE-2017-1000201 [MEDIUM] CVE-2017-1000201 tcmu-runner: UnregisterHandler dbus method in tcmu-runner daemon for non-existing handler causes DoS
CVE-2017-1000201 tcmu-runner: UnregisterHandler dbus method in tcmu-runner daemon for non-existing handler causes DoS
A local non-root user with access to the D-Bus system bus can call the
UnregisterHandler method implemented in the tcmu-runner daemon with the
name of an unknown tcmu runner handler as parameter and cause a NULL
pointer dereference.
Upstream patch:
https://github.com/open-iscsi/tcmu-runner/commit/e2d953050766ac538615a811c64b34358614edce
References:
http://seclists.org/oss-sec/2017/q3/207
Discussion:
Created tcmu-runner tracking bugs for this issue:
Affects: fedora-all [bug 1487255]
---
This issue has been addressed in the following products:
Red Hat Gluster Storage 3.3 for RHEL 7
Via RHSA-2017:3277 https://access.redhat.com/errata/RHSA-2017:3277
http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.htmlhttp://www.securityfocus.com/bid/95617http://www.securitytracker.com/id/1037639http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.htmlhttp://www.securityfocus.com/bid/95617http://www.securitytracker.com/id/1037639
2017-01-27
Published