CVE-2013-3828 – Oracle BPEL Process Manager ScriptServlet Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2013-3828
Unspecified vulnerability in the Oracle Web Services component in Oracle Fusion Middleware 10.1.3.5.0 and 11.1.1.6.0 allows remote attackers to affect confidentiality via unknown vectors related to Test Page. Vulnerabilidad no especificada en el componente Oracle Web Services de Oracle Fusion Middleware 10.1.3.5.0 y 11.1.1.6.0 permite a atacantes remotos afectar la confidencialidad a través de vectores relacionados con Test Page. This vulnerability allows remote attackers to obtain sensitive information on vulnerable installations of Oracle BPEL Process Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ScriptServlet. It suffers of a directory traversal vulnerability inside the query string which can lead to disclosure of credentials. • http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html http://www.securitytracker.com/id/1029190 •
CVE-2013-3770
https://notcve.org/view.php?id=CVE-2013-3770
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, and 11.1.1.7.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Server. NOTE: the previous information is from the October 2013 CPU. Oracle has not commented on claims from a third party that the issue is related to "iDoc script injection" in the (1) cs and (2) urm components, which allows attackers to read "sensitive" files, as demonstrated by obtaining the "AES encryption key and encrypted credentials" of the weblogic user. Vulnerabilidad sin especificar en el componente Oracle WebCenter Content en Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, y 11.1.1.7.0 permite a atacantes remotos comprometer la integridad y confidencialidad a través de vectores desconocidos relacionado con los Web Content Server. • http://osvdb.org/95271 http://secunia.com/advisories/54227 http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html http://www.securityfocus.com/bid/61228 http://www.securitytracker.com/id/1028801 http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1038 https://exchange.xforce.ibmcloud.com/vulnerabilities/85658 •
CVE-2013-3772
https://notcve.org/view.php?id=CVE-2013-3772
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, and 11.1.1.7.0 allows remote attackers to affect integrity via unknown vectors related to Web Forms. Vulnerabilidad sin especificar en el componente Oracle WebCenter Content en Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, y 11.1.1.7.0 permite a atacantes remotos comprometer la integridad a través de vectores desconocidos relacionado con los Web Forms. • http://osvdb.org/95274 http://secunia.com/advisories/54227 http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html http://www.securityfocus.com/bid/61220 http://www.securitytracker.com/id/1028801 https://exchange.xforce.ibmcloud.com/vulnerabilities/85661 •
CVE-2013-3769
https://notcve.org/view.php?id=CVE-2013-3769
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, and 11.1.1.7.0 allows remote attackers to affect integrity via unknown vectors related to Site Studio. Vulnerabilidad no especificada en el componente Oracle WebCenter Content en Oracle Fusion Middleware v10.1.3.5.1, v11.1.1.6.0, y v11.1.1.7.0 permite a atacantes remotos afectar la integridad mediante vectores relacionados con Site Studio. • http://osvdb.org/95273 http://secunia.com/advisories/54227 http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html http://www.securityfocus.com/bid/61223 http://www.securitytracker.com/id/1028801 https://exchange.xforce.ibmcloud.com/vulnerabilities/85660 •
CVE-2013-2390
https://notcve.org/view.php?id=CVE-2013-2390
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2, 10.3.5, 10.3.6, and 12.1.1 allows remote attackers to affect integrity via unknown vectors related to WebLogic Console, a different vulnerability than CVE-2013-1504. Vulnerabilidad sin especificar en el componente Oracle WebLogic Server en Oracle Fusion Middleware 10.0.2, 10.3.5, 10.3.6, y 12.1.1, permite a atacantes remotos comprometer la integridad a través de vectores desconocidos relacionados con Wevlogic Console. Vulnerabilidad distinta de CVE-2013-1504. • http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html •