« Volver al listado

CVE-2015-0393

Estado: ModificadaMedia (6)—

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to DB Privileges. NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that the PUBLIC role is granted the INDEX privilege for the DUAL table during a "seeded install," which allows remote authenticated users to gain SYSDBA privileges and execute arbitrary code.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-0393",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert_us@oracle.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2015-01-21T18:59:36.933",
  "references": [
    {
      "url": "http://www.databaseforensics.com/Oracle_Jan2015_CPU.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert_us@oracle.com"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert_us@oracle.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/72230",
      "source": "secalert_us@oracle.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1031579",
      "source": "secalert_us@oracle.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/100097",
      "source": "secalert_us@oracle.com"
    },
    {
      "url": "http://www.databaseforensics.com/Oracle_Jan2015_CPU.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/72230",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1031579",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/100097",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to DB Privileges.  NOTE: the previous information is from the January 2015 CPU. Oracle has not commented on the researcher's claim that the PUBLIC role is granted the INDEX privilege for the DUAL table during a \"seeded install,\" which allows remote authenticated users to gain SYSDBA privileges and execute arbitrary code."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad no especificada en el componente Oracle Applications DBA en Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, y 12.2.4 permite a usuarios remotos autenticados afectar la confidencialidad, la integridad y la disponibilidad a través de vectores desconocidos relacionados con privilegios DB. NOTA: la información anterior es de la CPU de enero del 2015. Oracle no ha comentado sobre la declaración del investigador original de que el rol PUBLIC se le cede el privilegio INDEX para la tabla DUAL durante una instalación inicializada ('seeded install,') lo que permite a usuarios remotos autenticados ganar privilegios SYSDBA y ejecutar código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T00:20:10.350",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80B61990-9CC2-4215-9879-AC817F4E6767"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:12.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C6BAB4D-1DF5-4ECB-A07E-297A94664BBE"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:12.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E42C3CE-CA98-4C13-B41E-DF7A3FEC560F"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:12.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99EF853E-9772-4678-88BB-5FEFE796D9AC"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:12.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86D2B444-B8D8-4A3D-BCCA-3B5280F05A38"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:12.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FDD0B52-77F6-4607-84F8-1BCF99DB1B23"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert_us@oracle.com"
}