Lucene search

K
cveOracleCVE-2010-4416
HistoryJan 19, 2011 - 4:00 p.m.

CVE-2010-4416

2011-01-1916:00:03
oracle
web.nvd.nist.gov
27
oracle
goldengate
veridata
vulnerability
remote attackers
availability
unknown vectors
buffer overflow
xml
soap request
nvd
cve-2010-4416

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.3

Confidence

Low

EPSS

0.942

Percentile

99.2%

Unspecified vulnerability in the Oracle GoldenGate Veridata component in Oracle Fusion Middleware 3.0.0.4 allows remote attackers to affect availability via unknown vectors related to Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party researcher that this is a buffer overflow via a crafted XML soap request and a value that does not contain the expected 0x20 terminator character.

Affected configurations

Nvd
Node
oraclefusion_middlewareMatch3.0.0.4
VendorProductVersionCPE
oraclefusion_middleware3.0.0.4cpe:2.3:a:oracle:fusion_middleware:3.0.0.4:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

AI Score

6.3

Confidence

Low

EPSS

0.942

Percentile

99.2%