PT-2016-5551 · Oracle · Oracle E-Business Suite

Publicado

2016-07-21

·

Atualizado

2017-09-01

·

CVE-2016-3532

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Oracle E-Business Suite versions 12.1.1 through 12.1.3
Description The issue affects confidentiality and integrity, and it is related to SDK client integration. There are claims that this issue involves multiple cross-site scripting (XSS) vulnerabilities, which allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Recommendations For Oracle E-Business Suite versions 12.1.1 through 12.1.3, update to a version that addresses the SDK client integration issue to prevent remote attackers from affecting confidentiality and integrity. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2016-3532

Produtos afetados

Oracle E-Business Suite