CVE-2015-4845
Oracle E-Business Suite 12.2.4 Database User Enumeration
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via vectors related to Java APIs - AOL/J. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to enumerate database users via a series of requests to Aoljtest.js.
Vulnerabilidad no especificada en el componente Oracle Application Object Library en Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3 y 12.2.4 permite a atacantes remotos afectar a la confidencialidad a través de vectores relacionados con APIs Java - AOL/J. NOTA: la información anterior es de la CPU de Octubre de 2015. Oracle no ha comentado sobre alegaciones de terceros que consideran que este problema permite a atacantes remotos enumerar los usuarios de la base de datos a través de una serie de peticiones a Aoljtest.js.
There is a script in EBS that is used to connect to the database and displays the connection status. Different connection results can help an attacker to find existing database accounts. Version 12.2.4 is affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-24 CVE Reserved
- 2015-10-21 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/134098/Oracle-E-Business-Suite-12.2.4-Database-User-Enumeration.html | X_refsource_misc |
|
http://seclists.org/fulldisclosure/2015/Oct/97 | Mailing List |
|
http://www.securityfocus.com/archive/1/536770/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/77249 | Vdb Entry | |
http://www.securitytracker.com/id/1033877 | Vdb Entry | |
https://erpscan.io/advisories/erpscan-15-025-oracle-e-business-suite-database-user-enumeration-vulnerability | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html | 2018-12-10 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | E-business Suite Search vendor "Oracle" for product "E-business Suite" | 11.5.10.2 Search vendor "Oracle" for product "E-business Suite" and version "11.5.10.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | E-business Suite Search vendor "Oracle" for product "E-business Suite" | 12.0.6 Search vendor "Oracle" for product "E-business Suite" and version "12.0.6" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | E-business Suite Search vendor "Oracle" for product "E-business Suite" | 12.1.3 Search vendor "Oracle" for product "E-business Suite" and version "12.1.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | E-business Suite Search vendor "Oracle" for product "E-business Suite" | 12.2.3 Search vendor "Oracle" for product "E-business Suite" and version "12.2.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | E-business Suite Search vendor "Oracle" for product "E-business Suite" | 12.2.4 Search vendor "Oracle" for product "E-business Suite" and version "12.2.4" | - |
Affected
|