PT-2016-2700 · Oracle · Oracle Weblogic Server

Publicado

2016-07-21

·

Atualizado

2018-10-30

·

CVE-2016-3586

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle WebLogic Server versions 10.3.6.0, 12.1.3.0, and 12.2.1.0
Description The issue affects the confidentiality, integrity, and availability of data. It is related to errors in the code of the Oracle WebLogic Server component, specifically in WLS Core Components. This allows remote attackers to exploit the issue, potentially leading to unauthorized access or control over the affected system. The estimated number of potentially affected devices and details about real-world incidents are not specified.
Recommendations For versions 10.3.6.0, 12.1.3.0, and 12.2.1.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-02094
CVE-2016-3586
ZDI-16-441

Produtos afetados

Oracle Weblogic Server