CVE-2017-3484
published 2017-04-24CVE-2017-3484: Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and…
PriorityP430medium5.4CVSS 3.0
AVNACLPRLUINSUCLILAN
EPSS
1.05%
60.4th percentile
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and Collateral). Supported versions that are affected are 12.0.0 and 12.1.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | flexcube_enterprise_limits_and_collateral_management | — | — |
| oracle | flexcube_enterprise_limits_and_collateral_management | — | — |
| oracle_corporation | flexcube_enterprise_limits_and_collateral_management | — | — |
| oracle_corporation | flexcube_enterprise_limits_and_collateral_management | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15649 kernel: Use-after-free in the af_packet.c
bugzilla·2017-10-20·CVSS 7.8
CVE-2017-15649 [HIGH] CVE-2017-15649 kernel: Use-after-free in the af_packet.c
CVE-2017-15649 kernel: Use-after-free in the af_packet.c
net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a use-after-free, a different vulnerability than CVE-2017-6346.
Upstream patches:
https://github.com/torvalds/linux/commit/008ba2a13f2d04c947adc536d19debb8fe66f110
https://github.com/torvalds/linux/commit/4971613c1639d8e5f102c4e797c3bf8f83a5a69e
https://github.com/torvalds/linux/commit/2bd624b4611ffee36422782d16e1c944d1351e98
References:
https://blogs.securiteam.com/index.php/archives/3484
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [b
Bugzilla
CVE-2017-2664 CloudForms: lack of RBAC on various methods in web UI
bugzilla·2017-03-23·CVSS 6.5
CVE-2017-2664 [MEDIUM] CVE-2017-2664 CloudForms: lack of RBAC on various methods in web UI
CVE-2017-2664 CloudForms: lack of RBAC on various methods in web UI
Libor Pichler and Martin Povolny report:
Cloudforms lacks RBAC controls on a variety of methods potentially allowing authenticated users to escalate privileges and use methods they should not have access to.
Discussion:
Acknowledgments:
Name: Libor Pichler (Red Hat), Martin Povolny (Red Hat)
---
*** Bug 1434771 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.8
Via RHSA-2017:1758 https://access.redhat.com/errata/RHSA-2017:1758
---
This issue has been addressed in the following products:
CloudForms Management Engine 5.7
Via RHSA-2017:3484 https://access.redhat.com/errata/RHSA-2017:3484
http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97786http://www.securitytracker.com/id/1038304http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlhttp://www.securityfocus.com/bid/97786http://www.securitytracker.com/id/1038304
2017-04-24
Published