|
CVE-2015-2918
|
Medium
|
2015-12-31
|
No exploit published
|
No public exploit
|
The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.
|
|
CVE-2015-2913
|
Medium
|
2015-12-31
|
No exploit published
|
No public exploit
|
server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 improperly relies on the java.util.Random class for generation of random Session ID values, which makes it easier for remote attackers to predict a value by determining the internal state of the PRNG in this class.
|
|
CVE-2015-5004
|
Medium
|
2015-12-15
|
No fix identified
|
No public exploit
|
The Edge Component Caching Proxy in IBM WebSphere Application Server (WAS) 8.0 before 8.0.0.12 and 8.5 before 8.5.5.8 does not properly encrypt data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
|
|
CVE-2015-5326
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.
|
|
CVE-2015-5324
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
|
|
CVE-2015-5323
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
|
|
CVE-2015-5322
|
Medium
|
2015-11-25
|
Protected by RASP
|
No public exploit
|
Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.
|
|
CVE-2015-5321
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to the pages.
|
|
CVE-2015-5320
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.
|
|
CVE-2015-5319
|
Medium
|
2015-11-25
|
Protected by RASP
|
No public exploit
|
XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read arbitrary files via a crafted job configuration that is then used in an "XML-aware tool," as demonstrated by get-job and update-job.
|
|
CVE-2015-5318
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which makes it easier for remote attackers to bypass the CSRF protection mechanism via a brute force attack.
|
|
CVE-2014-3665
|
Medium
|
2015-11-25
|
No exploit published
|
No public exploit
|
Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.
|
|
CVE-2015-5253
|
Medium
|
2015-11-18
|
No exploit published
|
No public exploit
|
The SAML Web SSO module in Apache CXF before 2.7.18, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote authenticated users to bypass authentication via a crafted SAML response with a valid signed assertion, related to a "wrapping attack."
|
|
CVE-2015-2017
|
Medium
|
2015-11-08
|
No fix identified
|
No public exploit
|
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
|
|
CVE-2015-5210
|
Medium
|
2015-11-02
|
No exploit published
|
No public exploit
|
Open redirect vulnerability in Apache Ambari before 2.1.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the targetURI parameter.
|
|
CVE-2015-1775
|
Medium
|
2015-11-02
|
No exploit published
|
No public exploit
|
Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.
|
|
CVE-2015-5262
|
Medium
|
2015-10-27
|
Mitigation candidate
|
No public exploit
|
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.
|
|
CVE-2015-5220
|
Medium
|
2015-10-27
|
No exploit published
|
No public exploit
|
The Web Console in Red Hat Enterprise Application Platform (EAP) before 6.4.4 and WildFly (formerly JBoss Application Server) allows remote attackers to cause a denial of service (memory consumption) via a large request header.
|
|
CVE-2015-5188
|
Medium
|
2015-10-27
|
No exploit published
|
No public exploit
|
Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentication of administrators for requests that make arbitrary changes to an instance via vectors involving a file upload using a multipart/form-data submission.
|
|
CVE-2015-5178
|
Medium
|
2015-10-27
|
No exploit published
|
No public exploit
|
The Management Console in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
|
|
CVE-2015-4916
|
Medium
|
2015-10-22
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2015-4906 and CVE-2015-4908.
|
|
CVE-2015-4912
|
Medium
|
2015-10-22
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2.2 and 11.1.2.3 allows remote attackers to affect confidentiality via vectors related to SSO Engine.
|
|
CVE-2015-4909
|
Medium
|
2015-10-22
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.4.0, 12.1.2.0.0, and 12.1.3.0.0 allows remote attackers to affect integrity via vectors related to ADF Faces.
|
|
CVE-2015-4908
|
Medium
|
2015-10-22
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 8u60 and JavaFX 2.2.85 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2015-4906 and CVE-2015-4916.
|
|
CVE-2015-4903
|
Medium
|
2015-10-22
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via vectors related to RMI.
|
|
CVE-2015-4902
|
Medium
|
2015-10-22
|
No fix identified
|
Exploited in the wild
|
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
|
|
CVE-2015-4899
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confidentiality via unknown vectors related to Security.
|
|
CVE-2015-4898
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via vectors related to Diagnostics and DMZ.
|
|
CVE-2015-4887
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ePerformance.
|
|
CVE-2015-4886
|
Medium
|
2015-10-21
|
Protected by RASP
|
No public exploit
|
Unspecified vulnerability in the Oracle Report Manager component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Reports Security. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to read arbitrary files, cause a denial of service, or conduct SMB Relay attacks via a crafted DTD in an XML request involving the OA_HTML/copxml servlet.
|
|
CVE-2015-4884
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via unknown vectors related to Single Signon.
|
|
CVE-2015-4882
|
Medium
|
2015-10-21
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect availability via vectors related to CORBA.
|
|
CVE-2015-4880
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server, a different vulnerability than CVE-2015-4867.
|
|
CVE-2015-4876
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via unknown vectors related to Pivot Grid.
|
|
CVE-2015-4875
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote attackers to affect availability via unknown vectors related to Agent Next Gen.
|
|
CVE-2015-4874
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen.
|
|
CVE-2015-4872
|
Medium
|
2015-10-21
|
Protected by RASP
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60; Java SE Embedded 8u51; and JRockit R28.3.7 allows remote attackers to affect integrity via unknown vectors related to Security.
|
|
CVE-2015-4871
|
Medium
|
2015-10-21
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 7u85 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
|
|
CVE-2015-4867
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server, a different vulnerability than CVE-2015-4880.
|
|
CVE-2015-4859
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Agent Next Gen.
|
|
CVE-2015-4854
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Single Signon. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is a cross-site scripting (XSS) vulnerability, which allows remote attackers to inject arbitrary web script or HTML via the Domain parameter in the CfgOCIReturn servlet.
|
|
CVE-2015-4851
|
Medium
|
2015-10-21
|
Protected by RASP
|
No public exploit
|
Unspecified vulnerability in the Oracle iSupplier Portal component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to XML input. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to read arbitrary files, cause a denial of service, or conduct SMB Relay attacks via a crafted DTD in an XML request to OA_HTML/oramipp_lpr.
|
|
CVE-2015-4850
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Talent Acquisition Management.
|
|
CVE-2015-4849
|
Medium
|
2015-10-21
|
Protected by RASP
|
No public exploit
|
Unspecified vulnerability in the Oracle Payments component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Punch-in. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to cause a denial of service or conduct SMB Relay attacks via a crafted DTD in an XML request to OA_HTML/IspPunchInServlet.
|
|
CVE-2015-4848
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via unknown vectors related to Integration with Peoplesoft.
|
|
CVE-2015-4847
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via vectors related to OCI.
|
|
CVE-2015-4845
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via vectors related to Java APIs - AOL/J. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue allows remote attackers to enumerate database users via a series of requests to Aoljtest.js.
|
|
CVE-2015-4842
|
Medium
|
2015-10-21
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via vectors related to JAXP.
|
|
CVE-2015-4841
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM IP2014 and IP2015 allows remote attackers to affect confidentiality via unknown vectors related to Services.
|
|
CVE-2015-4840
|
Medium
|
2015-10-21
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 7u85 and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via unknown vectors related to 2D.
|
|
CVE-2015-4838
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.4.0, 12.1.2.0.0, and 12.1.3.0.0 allows remote authenticated users to affect confidentiality via vectors related to ADF Faces.
|
|
CVE-2015-4832
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.7, 11.1.2.2, and 11.1.2.3 allows remote attackers to affect integrity via vectors related to OIM Legacy UI.
|
|
CVE-2015-4828
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise FSCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via vectors related to FIN Resource Management (Security).
|
|
CVE-2015-4827
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Retail Open Commerce Platform component in Oracle Retail Applications 3.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Framework.
|
|
CVE-2015-4818
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote authenticated users to affect confidentiality and integrity via vectors related to PIA Core Technology.
|
|
CVE-2015-4806
|
Medium
|
2015-10-21
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.
|
|
CVE-2015-4804
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Management component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.
|
|
CVE-2015-4799
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 7.6.2, 11.1.1.6.1, and 11.1.1.8.0 allows remote attackers to affect integrity via unknown vectors related to Security.
|
|
CVE-2015-4793
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Communications Convergence component in Oracle Communications Applications 2.0 and 3.0.1 allows remote attackers to affect confidentiality via unknown vectors related to Mail Proxy.
|
|
CVE-2015-4762
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.2.3 and 12.2.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Online patching.
|
|
CVE-2015-4734
|
Medium
|
2015-10-21
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 6u101, 7u85 and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality via vectors related to JGSS.
|
|
CVE-2015-1829
|
Medium
|
2015-10-21
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 10.1.3.5, 11.1.1.7, 11.1.1.9, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect availability via unknown vectors related to Web Listener.
|
|
CVE-2015-1813
|
Medium
|
2015-10-16
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1812.
|
|
CVE-2015-1812
|
Medium
|
2015-10-16
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1813.
|
|
CVE-2015-1810
|
Medium
|
2015-10-16
|
No exploit published
|
No public exploit
|
The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the "Jenkins' own user database" setting, which allows remote attackers to gain privileges by creating a reserved name.
|
|
CVE-2015-1806
|
Medium
|
2015-10-16
|
No exploit published
|
No public exploit
|
The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.
|
|
CVE-2015-5235
|
Medium
|
2015-10-09
|
No exploit published
|
No public exploit
|
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
|
|
CVE-2015-5234
|
Medium
|
2015-10-09
|
No exploit published
|
No public exploit
|
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
|
|
CVE-2015-3158
|
Medium
|
2015-08-26
|
Mitigation candidate
|
No public exploit
|
The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow.
|
|
CVE-2015-6524
|
Medium
|
2015-08-24
|
No exploit published
|
No public exploit
|
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.
|
|
CVE-2015-4938
|
Medium
|
2015-08-22
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 allows remote attackers to spoof servlets and obtain sensitive information via unspecified vectors.
|
|
CVE-2015-1932
|
Medium
|
2015-08-22
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7 allow remote attackers to obtain potentially sensitive information about the proxy-server software by reading the HTTP Via header.
|
|
CVE-2015-1830
|
Medium
|
2015-08-19
|
Protected by RASP
|
Working exploit published
|
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.
|
|
CVE-2015-6254
|
Medium
|
2015-08-17
|
No fix identified
|
No public exploit
|
The (1) Service Provider (SP) and (2) Identity Provider (IdP) in PicketLink before 2.7.0 does not ensure that the Destination attribute in a Response element in a SAML assertion matches the location from which the message was received, which allows remote attackers to have unspecified impact via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-0277 per ADT2 due to different vulnerability types.
|
|
CVE-2015-5531
|
Medium
|
2015-08-17
|
Protected by RASP
|
Working exploit published
|
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.
|
|
CVE-2015-0277
|
Medium
|
2015-08-17
|
Mitigation candidate
|
No public exploit
|
The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attackers to log in to other users' accounts via a crafted SAML assertion. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6254 for lack of validation for the Destination attribute in a Response element in a SAML assertion.
|
|
CVE-2015-5176
|
Medium
|
2015-08-11
|
No fix identified
|
No public exploit
|
The PortletRequestDispatcher in PortletBridge, as used in Red Hat JBoss Portal 6.2.0, does not properly enforce the security constraints of servlets, which allows remote attackers to gain access to resources via a request that asks to render a non-JSF resource.
|
|
CVE-2015-3267
|
Medium
|
2015-08-11
|
No fix identified
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in the 404 error page in Red Hat JBoss Operations Network before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
|
CVE-2015-4773
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Hyperion Common Security component in Oracle Hyperion 11.1.2.2, 11.1.2.3, and 11.1.2.4 allows remote authenticated users to affect availability via unknown vectors related to User Account Update.
|
|
CVE-2015-4768
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, and 6.3.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Diagnostics.
|
|
CVE-2015-4759
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality based on Trillium, a different vulnerability than CVE-2015-0443, CVE-2015-0444, CVE-2015-0445, CVE-2015-0446, CVE-2015-2634, CVE-2015-2635, CVE-2015-2636, and CVE-2015-4758.
|
|
CVE-2015-4758
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality based on Trillium, a different vulnerability than CVE-2015-0443, CVE-2015-0444, CVE-2015-0445, CVE-2015-0446, CVE-2015-2634, CVE-2015-2635, CVE-2015-2636, and CVE-2015-4759.
|
|
CVE-2015-4751
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.7 and 11.1.2.2 allows remote attackers to affect availability via unknown vectors related to Authentication Engine.
|
|
CVE-2015-4749
|
Medium
|
2015-07-16
|
Mitigation candidate
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect availability via vectors related to JNDI.
|
|
CVE-2015-4747
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7 and 12.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CEP system.
|
|
CVE-2015-4746
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Agile Product Lifecycle Management for Process component in Oracle Supply Chain Products Suite 6.0.0.7, 6.1.0.3, 6.1.1.5, and 6.2.0.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Global Spec Management.
|
|
CVE-2015-4743
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.2.3 allows remote authenticated users to affect confidentiality via unknown vectors related to AD Utilities.
|
|
CVE-2015-4742
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.2.4.0, 12.1.2.0.0, and 12.1.3.0.0 allows remote attackers to affect availability via vectors related to ADF Faces.
|
|
CVE-2015-4738
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise HCM Candidate Gateway component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.
|
|
CVE-2015-4735
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1, and EM DB Control 11.2.0.3 and 11.2.0.4, allows remote attackers to affect confidentiality via vectors related to RAC Management.
|
|
CVE-2015-4728
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Sourcing component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Bid/Quote creation.
|
|
CVE-2015-3244
|
Medium
|
2015-07-16
|
No exploit published
|
No public exploit
|
The Portlet Bridge for JavaServer Faces in Red Hat JBoss Portal 6.2.0, when used in portlets with the default resource serving for GenericPortlet, does not properly restrict access to restricted resources, which allows remote attackers to obtain sensitive information via a URL with a modified resource ID.
|
|
CVE-2015-2659
|
Medium
|
2015-07-16
|
Protected by RASP
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 8u45 and Java SE Embedded 8u33 allows remote attackers to affect availability via unknown vectors related to Security.
|
|
CVE-2015-2658
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Web Cache component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality via vectors related to SSL/TLS Support.
|
|
CVE-2015-2657
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, and 6.3.0 through 6.3.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Business Process Automation.
|
|
CVE-2015-2653
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce Platform 3.1.1, 3.1.2, 11.0, and 11.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Content Acquisition System.
|
|
CVE-2015-2652
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Web Management.
|
|
CVE-2015-2650
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect confidentiality via unknown vectors related to Multichannel Framework.
|
|
CVE-2015-2647
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1; EM Plugin for DB 12.1.0.5, 12.1.0.6, 12.1.0.7; and EM DB Control 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Management.
|
|
CVE-2015-2646
|
Medium
|
2015-07-16
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform: 11.1.0.1; EM Plugin for DB: 12.1.0.5, 12.1.0.6, 12.1.0.7; EM DB Control: 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote attackers to affect integrity via unknown vectors related to Content Management.
|