PT-2016-4292 · Oracle · Oracle Supply Chain Products Suite

Published

2016-01-21

·

Updated

2016-12-07

·

CVE-2016-0540

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Supply Chain Products Suite versions 11.5.10.2, 12.1, and 12.2
Description The issue affects confidentiality and is related to the UI Servlet in the Oracle Configurator component. The exact vectors of the attack are unknown.
Recommendations For Oracle Supply Chain Products Suite version 11.5.10.2, update to a version that includes the fix for this issue. For Oracle Supply Chain Products Suite version 12.1, update to a version that includes the fix for this issue. For Oracle Supply Chain Products Suite version 12.2, update to a version that includes the fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-0540

Affected Products

Oracle Supply Chain Products Suite