Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2016-3438

EPSS 0.39% · P60
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2016-3438

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1, and 12.2 allows remote attackers to affect confidentiality and integrity via vectors related to JRAD Heartbeat. NOTE: the previous information is from the April 2016 CPU. Oracle has not commented on third-party claims that that this issue involves multiple cross-site scripting (XSS) vulnerabilities, which allow remote attackers to inject arbitrary web script or HTML via three unspecified parameters in an unknown JSP file.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Oracle Supply Chain Products Suite Configurator组件安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Oracle Supply Chain Products Suite是美国甲骨文(Oracle)公司的一套供应链解决方案,该方案提供价值链计划、价值链执行、产品生命周期管理等功能。Oracle Configurator是其中的一个集成了订单管理、报价和销售的配置组件。 Oracle Supply Chain Products Suite 12.1版本和12.2版本的Oracle Configurator组件中的JRAD Heartbeat子组件存在安全漏洞。远程攻击者可利用该漏洞访问、更新、插入或删除数据
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2016-3438

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2016-3438

登录查看更多情报信息。

Same Patch Batch · n/a · 2016-04-21 · 118 CVEs total

CVE-2016-2006HPE Data Protector 安全漏洞
CVE-2016-3425Oracle Java SE、Java SE Embedded和JRockit JAXP子组件安全漏洞
CVE-2016-3423Oracle PeopleSoft Products PeopleSoft Enterprise PeopleTools组件安全漏洞
CVE-2016-3422Oracle Java SE 安全漏洞
CVE-2016-3421Oracle PeopleSoft Products PeopleSoft Enterprise PeopleTools组件安全漏洞
CVE-2016-3420Oracle Supply Chain Products Suite Agile PLM组件安全漏洞
CVE-2016-3419Oracle Sun Solaris Filesystem子组件安全漏洞
CVE-2016-3418Oracle Berkeley DB DataStore组件安全漏洞
CVE-2016-3417Oracle PeopleSoft Products PeopleSoft Enterprise PeopleTools组件安全漏洞
CVE-2016-3416Oracle Fusion Middleware WebLogic Server组件安全漏洞
CVE-2016-2294Accuenergy Acuvim II NET Firmware和IIR NET Firmware AXN-NET模块安全漏洞
CVE-2016-2293Accuenergy Acuvim II NET Firmware和IIR NET Firmware AXN-NET模块安全漏洞
CVE-2016-2280多款Honeywell Uniformance Process History Database产品缓冲区溢出漏洞
CVE-2016-2008HPE Data Protector 安全漏洞
CVE-2016-2007HPE Data Protector 安全漏洞
CVE-2016-0696Oracle Fusion Middleware WebLogic Server组件安全漏洞
CVE-2016-0699Oracle Financial Services Software Oracle FLEXCUBE Direct Banking组件安全漏洞
CVE-2016-0698Oracle PeopleSoft Products PeopleSoft Enterprise PeopleTools组件安全漏洞
CVE-2016-0697Oracle E-Business Suite Application Object Library组件安全漏洞
CVE-2016-0694Oracle Berkeley DB DataStore组件安全漏洞

Showing top 20 of 118 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2016-3438

No comments yet


Leave a comment