CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2015-3237 | Oracle Hyperion Essbase | Security (libcurl) | HTTP | Yes | 6.5 | Network | Low | None | None | Un-changed | Low | None | Low | 11.1.2.2 |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2016-3092 | Enterprise Manager Base Platform | Security Framework | HTTP | Yes | 7.5 | Network | Low | None | None | Un-changed | None | None | High | 12.1.0, 13.1.0, 13.2.0 | |
CVE-2017-3518 | Enterprise Manager Base Platform | Discovery Framework | HTTPS | Yes | 7.5 | Network | Low | None | None | Un-changed | None | None | High | 12.1.0, 13.1.0, 13.2.0 |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2017-3549 | Oracle Scripting | Scripting Administration | HTTP | Yes | 9.1 | Network | Low | None | None | Un-changed | High | High | None | 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 | |
CVE-2017-3555 | Oracle iReceivables | Self Registration | HTTP | Yes | 7.5 | Network | Low | None | None | Un-changed | None | None | High | 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 | |
CVE-2017-3393 | Oracle Advanced Outbound Telephony | Interaction History | HTTP | Yes | 7.1 | Network | Low | None | Required | Un-changed | Low | High | None | 12.2.3, 12.2.4, 12.2.5, 12.2.6 | |
CVE-2017-3550 | Oracle Customer Interaction History | Admin Console | HTTP | Yes | 7.1 | Network | Low | None | Required | Un-changed | Low | High | None | 12.1.1, 12.1.2, 12.1.3 | |
CVE-2017-3337 | Oracle Marketing | User Interface | HTTP | Yes | 7.1 | Network | Low | None | Required | Un-changed | Low | High | None | 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 | |
CVE-2017-3432 | Oracle One-to-One Fulfillment | Audience workbench | HTTP | Yes | 7.1 | Network | Low | None | Required | Un-changed | Low | High | None | 12.1.1, 12.1.2, 12.1.3 | |
CVE-2017-3557 | Oracle One-to-One Fulfillment | Print Server | HTTP | Yes | 7.1 | Network | Low | None | Required | Un-changed | Low | High | None | 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 | |
CVE-2017-3592 | Oracle Payables | Self Service Manager | HTTP | No | 6.5 | Network | Low | High | None | Un-changed | High | High | None | 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 | |
CVE-2017-3528 | Oracle Applications Framework | Popup windows (lists of values, datepicker, etc.) | HTTP | Yes | 5.4 | Network | Low | None | Required | Un-changed | Low | Low | None | 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 | |
CVE-2017-3515 | Oracle User Management | User Name/Password Management | HTTP | Yes | 5.4 | Network | Low | None | Required | Un-changed | Low | Low | None | 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 | |
CVE-2017-3556 | Oracle Application Object Library | File Management | HTTP | Yes | 5.3 | Network | Low | None | None | Un-changed | Low | None | None | 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2017-3530 | Oracle Transportation Manager | Security | HTTP | No | 6.1 | Network | Low | High | Required | Un-changed | High | High | None | 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0, 6.4.1, 6.4.2 |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2017-3519 | PeopleSoft Enterprise PeopleTools | Security | HTTP | Yes | 7.5 | Network | Low | None | None | Un-changed | High | None | None | 8.54, 8.55 | |
CVE-2017-3547 | PeopleSoft Enterprise PeopleTools | MultiChannel Framework | HTTP | Yes | 7.4 | Network | Low | None | Required | Changed | None | High | None | 8.54, 8.55 | |
CVE-2017-3577 | PeopleSoft Enterprise CS Campus Community | Frameworks | HTTP | No | 6.5 | Network | Low | High | None | Un-changed | High | High | None | 9.2 | |
CVE-2017-3570 | PeopleSoft Enterprise FSCM | eSettlements | HTTP | No | 6.5 | Network | Low | High | None | Un-changed | High | High | None | 9.1 | |
CVE-2017-3520 | PeopleSoft Enterprise PeopleTools | Fluid Core | HTTP | Yes | 6.5 | Network | Low | None | Required | Un-changed | None | High | None | 8.54, 8.55 | |
CVE-2017-3548 | PeopleSoft Enterprise PeopleTools | Integration Broker | HTTP | Yes | 6.5 | Network | Low | None | None | Un-changed | Low | None | Low | 8.54, 8.55 | |
CVE-2017-3546 | PeopleSoft Enterprise PeopleTools | MultiChannel Framework | HTTP | Yes | 6.5 | Network | Low | None | None | Un-changed | Low | Low | None | 8.54, 8.55 | |
CVE-2014-3596 | PeopleSoft Enterprise PeopleTools | Portal | HTTP | Yes | 6.5 | Network | Low | None | None | Un-changed | Low | Low | None | 8.54, 8.55 | |
CVE-2017-3521 | PeopleSoft Enterprise SCM Purchasing | Supplier Registration | HTTP | No | 6.5 | Network | Low | High | None | Un-changed | High | High | None | 9.2 | |
CVE-2017-3525 | PeopleSoft Enterprise SCM Service Procurement | Usability | HTTP | No | 6.5 | Network | Low | High | None | Un-changed | High | High | None | 9.2 | |
CVE-2017-3524 | PeopleSoft Enterprise SCM Strategic Sourcing | Bidder Registration | HTTP | No | 6.5 | Network | Low | High | None | Un-changed | High | High | None | 9.2 | |
CVE-2017-3571 | PeopleSoft Enterprise SCM eBill Payment | Security | HTTP | No | 6.5 | Network | Low | High | None | Un-changed | High | High | None | 9.2 | |
CVE-2017-3522 | PeopleSoft Enterprise SCM eSupplier Connection | Vendor | HTTP | No | 6.5 | Network | Low | High | None | Un-changed | High | High | None | 9.2 | |
CVE-2017-3502 | PeopleSoft Enterprise FIN Receivables | Receivables | HTTP | Yes | 5.3 | Network | Low | None | None | Un-changed | None | Low | None | 9.2 | |
CVE-2017-3527 | PeopleSoft Enterprise PeopleTools | Fluid Core | HTTP | Yes | 5.3 | Network | Low | None | None | Un-changed | Low | None | None | 8.54, 8.55 | |
CVE-2017-3536 | PeopleSoft Enterprise PeopleTools | Security | HTTP | No | 4.6 | Network | Low | Low | Required | Un-changed | Low | Low | None | 8.54, 8.55 |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2017-3517 | JD Edwards EnterpriseOne Tools | Web Runtime SEC | HTTP | Yes | 6.5 | Network | Low | None | None | Un-changed | Low | None | Low | 9.2 |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2017-5638 | Siebel Apps - E-Billing | Security (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 6.1, 6.2, 7.0, 7.1 |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2017-3572 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | MDEX | HTTP | Yes | 7.5 | Network | Low | None | None | Un-changed | None | None | High | 6.2.2, 6.3.0, 6.4.1.2, 6.5.0, 6.5.1, 6.5.2 | |
CVE-2016-6304 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | MDEX | HTTPS | Yes | 7.5 | Network | Low | None | None | Un-changed | None | None | High | 6.2.2, 6.3.0, 6.4.1.2, 6.5.0, 6.5.1, 6.5.2 | |
CVE-2016-2107 | Oracle Commerce Guided Search / Oracle Commerce Experience Manager | Platform Services | HTTPS | Yes | 5.9 | Network | High | None | None | Un-changed | High | None | None | 6.1.4, 11.0, 11.1, 11.2 |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2017-5638 | Oracle Communications Policy Management | Security (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 12.2 | |
CVE-2016-0729 | Oracle Communications ASAP | Security (Xerces) | HTTP | Yes | 9.8 | Network | Low | None | None | Un-changed | High | High | High | 7.0, 7.2, 7.3 | |
CVE-2016-0635 | Oracle Communications Network Integrity | Security (Spring) | HTTP | No | 8.8 | Network | Low | Low | None | Un-changed | High | High | High | 7.3.0, 7.2.4 | |
CVE-2016-3092 | Oracle Communications Service Broker Engineered System Edition | Install (Apache Commons FileUpload) | HTTP | Yes | 7.5 | Network | Low | None | None | Un-changed | None | None | High | 6.0, 6.1 | |
CVE-2013-5209 | Oracle Communications Session Border Controller | Sysadmin (SCTP) | SCTP | Yes | 7.5 | Network | Low | None | None | Un-changed | High | None | None | SCZ7.3.0, SCZ7.4.0 | |
CVE-2016-6304 | Oracle Communications Session Border Controller | Routing (OpenSSL) | TLS | Yes | 7.5 | Network | Low | None | None | Un-changed | None | None | High | SCZ7.3.0, SCZ7.4.0 | |
CVE-2012-0920 | Oracle Communications Session Border Controller | Sysadmin (Dropbear) | SSH | No | 7.1 | Network | High | Low | Required | Un-changed | High | High | High | SCZ7.3.0, SCZ7.4.0 | |
CVE-2017-3732 | Oracle Communications Security Gateway | Routing (OpenSSL) | TLS | Yes | 5.9 | Network | High | None | None | Un-changed | High | None | None | 3.0.0 | |
CVE-2013-2566 | Oracle Communications Session Border Controller | Sysadmin | SSH | Yes | 5.9 | Network | High | None | None | Un-changed | High | None | None | SCZ7.3.0, SCZ7.4.0 | |
CVE-2017-3470 | Oracle Communications Security Gateway | Network | ICMP Ping | Yes | 5.3 | Network | Low | None | None | Un-changed | None | None | Low | 3.0.0 | |
CVE-2015-0204 | Oracle Communications Session Border Controller | Routing | TLS | Yes | 5.3 | Network | Low | None | None | Un-changed | None | Low | None | SCZ7.3.0, SCZ7.4.0 |
-------------------------
Appendix - Oracle Financial Services Applications
Oracle Financial Services Applications Executive Summary
This Critical Patch Update contains 47 new security fixes for Oracle Financial Services Applications. 25 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here.
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2017-5638 | Oracle FLEXCUBE Private Banking | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 12.0.1, 12.0.2, 12.0.3, 12.1.0 | |
CVE-2017-5638 | Oracle Financial Services Analytical Applications Infrastructure | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 7.3.3, 7.3.4, 7.3.5 | |
CVE-2017-5638 | Oracle Financial Services Asset Liability Management | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 6.0.0, 6.1.0, 6.1.1, 8.0.1, 8.0.2, 8.0.3, 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Basel Regulatory Capital Basic | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 6.1.2, 6.1.3, 8.0.2, 8.0.3 | |
CVE-2017-5638 | Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 6.1.2, 6.1.3, 8.0.2, 8.0.3 | |
CVE-2017-5638 | Oracle Financial Services Data Foundation | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 8.0.1, 8.0.2, 8.0.3, 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Data Integration Hub | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 8.0.1, 8.0.2, 8.0.3, 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Enterprise Financial Performance Analytics | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 8.0.0 to 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Funds Transfer Pricing | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 6.0.0, 6.1.0, 6.1.1, 8.0.1, 8.0.2, 8.0.3, 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Hedge Management and IFRS Valuations | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 6.1.1, 8.0.1, 8.0.2, 8.0.3, 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Institutional Performance Analytics | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 8.0.0 to 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Liquidity Risk Management | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 8.0.1, 8.0.2, 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Loan Loss Forecasting and Provisioning | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 1.5.0, 1.5.1, 8.0.1, 8.0.2, 8.0.3, 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Pricing Management/Transfer Pricing Component | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 8.0.0 to 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Profitability Management | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 6.0.0, 6.1.0, 6.1.1, 8.0.1, 8.0.2, 8.0.3, 8.0.4 | |
CVE-2017-5638 | Oracle Financial Services Reconciliation Framework | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 8.0.0, 8.0.1, 8.0.2 | |
CVE-2017-5638 | Oracle Financial Services Retail Customer Analytics | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 8.0.0 to 8.0.3 | |
CVE-2017-5638 | Oracle Financial Services Retail Performance Analytics | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 8.0.0 to 8.0.4 | |
CVE-2017-5638 | Oracle Insurance Data Foundation | Core (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 8.0.1, 8.0.2, 8.0.3, 8.0.4 | |
CVE-2016-0635 | Oracle FLEXCUBE Private Banking | Core (Spring Framework) | HTTP | No | 8.8 | Network | Low | Low | None | Un-changed | High | High | High | 12.0.1, 12.0.2, 12.0.3, 12.1.0 | |
CVE-2017-3493 | Oracle FLEXCUBE Enterprise Limits and Collateral Management | Infrastructure | HTTP | No | 8.5 | Network | Low | Low | None | Changed | High | None | Low | 12.0.0, 12.1.0 | |
CVE-2017-3472 | Oracle FLEXCUBE Private Banking | Portfolio Management | HTTP | No | 8.1 | Network | Low | Low | None | Un-changed | High | High | None | 2.0.0, 2.0.1, 2.2.0.1, 12.0.1 | |
CVE-2017-3476 | Oracle FLEXCUBE Private Banking | Miscellaneous | HTTP | No | 7.1 | Network | Low | Low | None | Un-changed | High | Low | None | 2.0.0, 2.0.1, 2.2.0.1, 12.0.1 | |
CVE-2017-3485 | Oracle FLEXCUBE Universal Banking | Infrastructure | HTTP | No | 6.8 | Network | High | Low | None | Un-changed | None | High | High | 11.3.0, 11.4.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 | |
CVE-2017-3491 | Oracle FLEXCUBE Enterprise Limits and Collateral Management | Limits and Collateral | HTTP | No | 6.5 | Network | Low | Low | None | Un-changed | High | None | None | 12.0.1, 12.1.0 | |
CVE-2017-3488 | Oracle FLEXCUBE Investor Servicing | Unit Trust | HTTP | No | 6.5 | Network | Low | Low | None | Un-changed | None | High | None | 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0, 12.3.0 | |
CVE-2017-3534 | Oracle FLEXCUBE Universal Banking | Infrastructure | HTTP | No | 6.5 | Network | Low | Low | None | Un-changed | High | None | None | 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 | |
CVE-2017-3496 | Oracle FLEXCUBE Enterprise Limits and Collateral Management | Infrastructure | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 12.0.0, 12.1.0 | |
CVE-2017-3492 | Oracle FLEXCUBE Enterprise Limits and Collateral Management | Infrastructure | HTTP | No | 5.4 | Network | Low | Low | None | Un-changed | Low | Low | None | 12.0.0, 12.1.0 | |
CVE-2017-3484 | Oracle FLEXCUBE Enterprise Limits and Collateral Management | Limits and Collateral | HTTP | No | 5.4 | Network | Low | Low | None | Un-changed | Low | Low | None | 12.0.0, 12.1.0 | |
CVE-2017-3489 | Oracle FLEXCUBE Investor Servicing | Security Management System | HTTP | No | 5.4 | Network | Low | Low | None | Un-changed | Low | Low | None | 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0, 12.3.0 | |
CVE-2017-3288 | Oracle FLEXCUBE Investor Servicing | Unit Trust | HTTP | No | 5.4 | Network | Low | Low | None | Un-changed | Low | Low | None | 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0, 12.3.0 | |
CVE-2017-3478 | Oracle FLEXCUBE Private Banking | Miscellaneous | HTTP | No | 5.4 | Network | Low | Low | None | Un-changed | Low | Low | None | 12.0.0, 12.1.0 | |
CVE-2017-3479 | Oracle FLEXCUBE Private Banking | Miscellaneous | HTTP | No | 5.4 | Network | Low | Low | None | Un-changed | None | Low | Low | 2.0.0, 2.0.1, 2.2.0.1, 12.0.1 | |
CVE-2017-3482 | Oracle FLEXCUBE Universal Banking | Infrastructure | HTTP | No | 5.4 | Network | Low | Low | Required | Changed | Low | Low | None | 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 | |
CVE-2017-3475 | Oracle FLEXCUBE Private Banking | Miscellaneous | HTTP | No | 5.0 | Network | Low | Low | None | Changed | None | None | Low | 2.0.0, 2.0.1, 2.2.0.1, 12.0.1 | |
CVE-2017-3495 | Oracle FLEXCUBE Direct Banking | Pre-Login | HTTP | Yes | 4.7 | Network | Low | None | Required | Changed | Low | None | None | 12.0.2, 12.0.3 | |
CVE-2017-3471 | Oracle FLEXCUBE Private Banking | Miscellaneous | HTTP | Yes | 4.7 | Network | Low | None | Required | Changed | None | Low | None | 12.0.0, 12.1.0 | |
CVE-2017-3480 | Oracle FLEXCUBE Universal Banking | Infrastructure | HTTP | Yes | 4.7 | Network | Low | None | Required | Changed | Low | None | None | 11.3.0, 11.4.0, 12.0.1 | |
CVE-2017-3535 | Oracle FLEXCUBE Universal Banking | Infrastructure | HTTP | Yes | 4.7 | Network | Low | None | Required | Changed | Low | None | None | 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3 | |
CVE-2017-3494 | Oracle FLEXCUBE Universal Banking | Retail Teller | HTTP | Yes | 4.7 | Network | Low | None | Required | Changed | Low | None | None | 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3 | |
CVE-2017-3483 | Oracle FLEXCUBE Enterprise Limits and Collateral Management | Limits and Collateral | None | No | 4.4 | Local | Low | High | None | Un-changed | High | None | None | 12.0.0, 12.1.0 | |
CVE-2017-3473 | Oracle FLEXCUBE Private Banking | Miscellaneous | HTTP | No | 4.3 | Network | Low | Low | None | Un-changed | Low | None | None | 2.0.0, 2.0.1, 2.2.0.1, 12.0.1 | |
CVE-2017-3481 | Oracle FLEXCUBE Universal Banking | Infrastructure | HTTP | No | 4.3 | Network | Low | Low | None | Un-changed | None | None | Low | 11.3.0, 11.4.0, 12.0.1 | |
CVE-2017-3477 | Oracle FLEXCUBE Private Banking | Miscellaneous | HTTP | No | 4.2 | Network | High | Low | None | Un-changed | Low | Low | None | 12.0.0, 12.1.0 | |
CVE-2017-3490 | Oracle FLEXCUBE Enterprise Limits and Collateral Management | Limits and Collateral | HTTP | No | 3.1 | Network | High | Low | None | Un-changed | Low | None | None | 12.0.0, 12.1.0 | |
CVE-2017-3487 | Oracle FLEXCUBE Investor Servicing | Unit Trust | HTTP | No | 3.1 | Network | High | Low | None | Un-changed | None | Low | None | 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0, 12.3.0 |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2016-3092 | Oracle Healthcare Master Person Index | Cleanser, Profiler (Apache Commons FileUpload) | HTTP | Yes | 7.5 | Network | Low | None | None | Un-changed | None | None | High | Prior to and 2.0.1.x, 3.0.0.x and 4.0.1.x |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2017-3574 | Oracle Hospitality OPERA 5 Property Services | OPERA License code configuration | HTTP | No | 7.1 | Network | Low | Low | None | Un-changed | High | Low | None | 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x, 5.5.1.x | |
CVE-2017-3568 | Oracle Hospitality OPERA 5 Property Services | OPERA Printing and Login | None | No | 6.5 | Local | High | None | Required | Un-changed | High | High | Low | 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x, 5.5.1.x | |
CVE-2017-3573 | Oracle Hospitality OPERA 5 Property Services | OPERA Printing | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x, 5.5.1.x | |
CVE-2017-3569 | Oracle Hospitality OPERA 5 Property Services | OPERA Business Events | HTTP | No | 5.4 | Network | Low | Low | None | Un-changed | Low | Low | None | 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x, 5.5.1.x | |
CVE-2017-3552 | Oracle Hospitality OPERA 5 Property Services | OPERA Room Image/Picture Setup | HTTP | No | 4.3 | Network | Low | Low | None | Un-changed | Low | None | None | 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x, 5.5.1.x | |
CVE-2017-3560 | Oracle Hospitality OPERA 5 Property Services | OXI Interface | HTTP | No | 4.3 | Network | Low | Low | None | Un-changed | Low | None | None | 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x, 5.5.1.x |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2015-7940 | Oracle Insurance Istream | IStream Publisher (Bouncy Castle) | HTTP | No | 6.5 | Network | Low | Low | None | Un-changed | High | None | None | 4.3.2 and prior |
CVE# | Component | Sub-component | Protocol | RemoteExploitwithoutAuth.? | CVSS VERSION 3.0 RISK (see Risk Matrix Definitions) | Supported Versions Affected | Notes | ||||||||
BaseScore | AttackVector | AttackComplex | PrivsReq'd | UserInteract | Scope | Confid-entiality | Inte-grity | Avail-ability | |||||||
CVE-2017-5638 | Oracle Retail XBRi Loss Prevention | Internal Operations (Struts 2) | HTTP | Yes | 10.0 | Network | Low | None | None | Changed | High | High | High | 10.0.1, 10.5.0, 10.6.0, 10.7.0, 10.8.0, 10.8.1 | |
CVE-2016-0635 | Oracle Retail Back Office | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un-changed | High | High | High | 14.1 | |
CVE-2016-0635 | Oracle Retail Invoice Matching | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un-changed | High | High | High | 13.2, 14.0, 14.1 | |
CVE-2016-0635 | Oracle Retail Point-of-Service | Infrastructure | HTTP | No | 8.8 | Network | Low | Low | None | Un-changed | High | High | High | 14.1.3 | |
CVE-2016-0635 | Oracle Retail Point-of-Service | Mobile POS | HTTP | No | 8.8 | Network | Low | Low | None | Un-changed | High | High | High | 14.1.3 | |
CVE-2016-0635 | Oracle Retail Returns Management | Security | HTTP | No | 8.8 | Network | Low | Low | None | Un-changed | High | High | High | 14.1 | |
CVE-2016-3506 | MICROS Lucas | Security | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 2.9.5.1, 2.9.5.2, 2.9.5.3, 2.9.5.4, 2.9.5.5 | |
CVE-2016-3506 | MICROS Relate CRM Software | Web Services | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 10.0, 10.5, 10.8, 11.0, 11.1, 11.4, 15.0 | |
CVE-2016-3506 | MICROS XBR | Database | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 10.0.1, 10.5.0, 10.6.0, 10.7.7, 10.8.0, 10.8.1 | |
CVE-2016-3506 | MICROS Xstore Payment | Security | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 5.5, 6.0, 6.5, 7.0, 7.1, 15.0, 16.0 | |
CVE-2016-3506 | Oracle Retail Advanced Inventory Planning | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.1, 15.0 | |
CVE-2016-3506 | Oracle Retail Advanced Science Engine | General | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.1 | |
CVE-2016-3506 | Oracle Retail Analytic Parameter Calculator - RO | Data Interface | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 15.0 | |
CVE-2016-3506 | Oracle Retail Analytic Parameter Calculator - RO | Installation/Configuration | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 15.0 | |
CVE-2016-3506 | Oracle Retail Analytics | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.0, 14.1, 15.0, 16.0 | |
CVE-2016-3506 | Oracle Retail Assortment Planning | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.1.3, 15.0.1, 16.0.0 | |
CVE-2016-3506 | Oracle Retail Category Management | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 13.2, 13.3, 14.0, 14.1 | |
CVE-2016-3506 | Oracle Retail Category Management Planning & Optimization | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 15.0 | |
CVE-2016-3506 | Oracle Retail Customer Insights | Installer | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 15.0 | |
CVE-2016-2510 | Oracle Retail Customer Management and Segmentation Foundation | Web Services | HTTPS | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 15.0 | |
CVE-2016-3506 | Oracle Retail Demand Forecasting | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.1.3, 15.0.2 | |
CVE-2016-3506 | Oracle Retail Item Planning | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.1.3, 15.0.2 | |
CVE-2016-3506 | Oracle Retail Macro Space Optimization | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 15.0.2 | |
CVE-2016-3506 | Oracle Retail Merchandise Financial Planning | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.1.3, 15.0.2 | |
CVE-2016-3506 | Oracle Retail Merchandising Insights | Installer | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 15.0 | |
CVE-2016-3506 | Oracle Retail Order Broker | Order Broker Foundation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 5.1, 5.2, 15.0, 16.0 | |
CVE-2016-3506 | Oracle Retail Predictive Application Server | Installer - Server | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 13.1, 13.2, 13.3, 13.4, 14.0, 14.1, 15.0 | |
CVE-2016-3506 | Oracle Retail Regular Price Optimization | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.1.3, 15.0.2 | |
CVE-2016-3506 | Oracle Retail Replenishment Optimization | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.1.3, 15.0.2 | |
CVE-2016-3506 | Oracle Retail Size Profile Optimization | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.1.3, 15.0.2 | |
CVE-2016-3506 | Oracle Retail Store Inventory | Installation | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 14.1, 15.0, 16.0 | |
CVE-2016-3506 | Oracle Retail Xstore Point of Service | Point of Sale | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 5.5, 6.0, 6.5, 7.1, 15.0 | |
CVE-2016-3506 | Oracle Retail Xstore Point of Service | Point of Sale | Oracle Net | Yes | 8.1 | Network | High | None | None | Un-changed | High | High | High | 5.5, 6.0, 6.5, 7.0, 7.1, 15.0, 16.0 | |
CVE-2016-1181 | Oracle Retail Invoice Matching | Security | None | No | 7.8 | Local | Low | Low | None | Un-changed | High | High | High | 12.0, 13.0, 13.1, 13.2, 14.0, 14.1 | |
CVE-2017-3254 | Oracle Retail Invoice Matching | Security | HTTP | Yes | 7.6 | Network | Low | None | Required | Un-changed | High | Low | Low | 12.0, 13.0 | |
CVE-2015-7940 | Oracle Retail Open Commerce Platform | Framework | HTTP | Yes | 7.5 | Network | Low | None | None | Un-changed | High | None | None | 4.0, 5.0, 5.1, 5.3, 6.0 | |
CVE-2015-0204 | Oracle Retail Predictive Application Server | RPAS Server | SSL/TLS | Yes | 7.5 | Network | Low | None | None | Un-changed | None | None | High | 13.3.3, 13.4.3, 14.0.3, 14.1.3, 15.0.2, 16.0.0 | |
CVE-2017-3532 | Oracle Retail Warehouse Management System | Security | HTTP | Yes | 6.1 | Network | Low | None | Required | Changed | Low | Low | None | 13.2, 14.0, 15.0 | |
CVE-2017-3451 | Oracle Retail Open Commerce Platform | Web | HTTP | No | 5.4 | Network | Low | Low | Required | Changed | Low | Low | None | 4.0, 5.0, 5.1, 5.3, 6.0, 6.1, 15.0, 16.0 |
-------------------------
[table=955,#ffffff,,1][tr][td]
[table=955,#ffffff,,1] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Appendix - Oracle Support Tools Oracle Support Tools Executive Summary This Critical Patch Update contains 13 new security fixes for Oracle Support Tools. 4 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials. The English text form of this Risk Matrix can be found here. Oracle Support Tools Risk Matrix
Additional CVEs addressed are below:
|
版权声明:本文内容由阿里云实名注册用户自发贡献,版权归原作者所有,阿里云开发者社区不拥有其著作权,亦不承担相应法律责任。具体规则请查看《阿里云开发者社区用户服务协议》和《阿里云开发者社区知识产权保护指引》。如果您发现本社区中有涉嫌抄袭的内容,填写侵权投诉表单进行举报,一经查实,本社区将立刻删除涉嫌侵权内容。