CVE-2007-3866
Estado: ModificadaAlta (7.5)—
Múltiples vulnerabilidades sin especificar en el Oracle E-Business Suite 11.5.10CU2 y 12.0.1 permiten a atacantes remotos tener un impacto desconocido a través de (a) el Oracle Configurator (APPS02), (b) el Oracle iExpenses (APPS03), (c) el Oracle Application Object Library (APPS09) y (1) APPS12, (2) APPS13 y (3) APPS14 en el (d) Oracle Payables.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.74%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143
- http://secunia.com/advisories/26114
- http://secunia.com/advisories/26166
- http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdf
- http://www.oracle.com/technetwork/topics/security/cpujul2007-087014.html
- http://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html
- http://www.securityfocus.com/archive/1/474515/100/0/threaded
- http://www.securitytracker.com/id?1018415
- http://www.us-cert.gov/cas/techalerts/TA07-200A.html
- http://www.vupen.com/english/advisories/2007/2562
- http://www.vupen.com/english/advisories/2007/2635
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35490
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143
- http://secunia.com/advisories/26114
- http://secunia.com/advisories/26166
- http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdf
- http://www.oracle.com/technetwork/topics/security/cpujul2007-087014.html
- http://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html
- http://www.securityfocus.com/archive/1/474515/100/0/threaded
- http://www.securitytracker.com/id?1018415
- http://www.us-cert.gov/cas/techalerts/TA07-200A.html
- http://www.vupen.com/english/advisories/2007/2562
- http://www.vupen.com/english/advisories/2007/2635
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35490
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-3866",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-07-18T19:30:00.000",
"references": [
{
"url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26114",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/26166",
"source": "cve@mitre.org"
},
{
"url": "http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdf",
"source": "cve@mitre.org"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/cpujul2007-087014.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/474515/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1018415",
"source": "cve@mitre.org"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA07-200A.html",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2562",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2635",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35490",
"source": "cve@mitre.org"
},
{
"url": "http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26114",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/26166",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdf",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.oracle.com/technetwork/topics/security/cpujul2007-087014.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/474515/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1018415",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA07-200A.html",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2562",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/2635",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/35490",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 and 12.0.1 allow remote attackers to have an unknown impact via (a) Oracle Configurator (APPS02), (b) Oracle iExpenses (APPS03), (c) Oracle Application Object Library (APPS09), and (1) APPS12, (2) APPS13, and (3) APPS14 in (d) Oracle Payables."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades sin especificar en el Oracle E-Business Suite 11.5.10CU2 y 12.0.1 permiten a atacantes remotos tener un impacto desconocido a través de (a) el Oracle Configurator (APPS02), (b) el Oracle iExpenses (APPS03), (c) el Oracle Application Object Library (APPS09) y (1) APPS12, (2) APPS13 y (3) APPS14 en el (d) Oracle Payables."
}
],
"lastModified": "2026-06-16T22:42:56.093",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80B61990-9CC2-4215-9879-AC817F4E6767"
},
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:12.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "610AE265-C18D-4895-8034-5DB331DC68DF"
}
],
"operator": "OR"
}
]
}
],
"evaluatorImpact": "As the impact type is unspecified, it has been set to a default value of \"Obtain Other Access (e.g. application account).\"",
"sourceIdentifier": "cve@mitre.org"
}