Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2015-4854

EPSS 0.56% · P68
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2015-4854

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Single Signon. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is a cross-site scripting (XSS) vulnerability, which allows remote attackers to inject arbitrary web script or HTML via the Domain parameter in the CfgOCIReturn servlet.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Oracle E-Business Suite Application Object Library组件安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Oracle E-Business Suite(电子商务套件)是美国甲骨文(Oracle)公司的一套全面集成式的全球业务管理软件。Oracle Application Object Library(AOL,应用程序对象库)是其中的一个系统管理组件。 Oracle E-Business Suite的Oracle AOL组件中的Single Signon子组件中存在安全漏洞。远程攻击者可利用该漏洞更新、插入或删除数据,影响数据的完整性。以下版本受到影响:Oracle E-Business Suite 12.0
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2015-4854

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2015-4854

Please Login to view more intelligence information

Same Patch Batch · n/a · 2015-10-21 · 136 CVEs total

CVE-2015-4762Oracle E-Business Suite Applications DBA组件安全漏洞
CVE-2015-4805Oracle Java SE和Java SE Embedded Serialization子组件安全漏洞
CVE-2015-4804Oracle PeopleSoft Enterprise HCM Talent Acquistion Management组件安全漏洞
CVE-2015-4803Oracle Java SE、Java SE Embedded和JRockit JAXP子组件拒绝服务漏洞
CVE-2015-4802Oracle MySQL Server Server : Partition子组件安全漏洞
CVE-2015-4801Oracle Sun Solaris Kernel Zones子组件安全漏洞
CVE-2015-4800Oracle MySQL Server Server : Optimizer子组件拒绝服务漏洞
CVE-2015-4799Oracle Fusion Middleware WebCenter Sites组件安全漏洞
CVE-2015-4798Oracle E-Business Suite Applications Technology Stack组件拒绝服务漏洞
CVE-2015-4797Oracle Supply Chain Products Suite Agile PLM组件安全漏洞
CVE-2015-4796Oracle Database Server Java VM组件安全漏洞
CVE-2015-4795Oracle Industry Applications Utilities Work and Asset Management组件安全漏洞
CVE-2015-4794Oracle Database Server Java VM组件安全漏洞
CVE-2015-4793Oracle Communications Applications Communications Convergence组件安全漏洞
CVE-2015-4792Oracle MySQL Server Server : Partition子组件拒绝服务漏洞
CVE-2015-4791Oracle MySQL Server Server : Security : Privileges子组件拒绝服务漏洞
CVE-2015-4766Oracle MySQL Server Server : Security : Firewall子组件拒绝服务漏洞
CVE-2015-4914Oracle Fusion Middleware Oracle HTTP Server组件安全漏洞
CVE-2015-4912Oracle Fusion Middleware Oracle Access Manager组件安全漏洞
CVE-2015-4913Oracle MySQL Server 远程拒绝服务漏洞

Showing top 20 of 136 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2015-4854

No comments yet


Leave a comment