Lucene search

K
cveOracleCVE-2013-3758
HistoryJul 17, 2013 - 1:41 p.m.

CVE-2013-3758

2013-07-1713:41:16
oracle
web.nvd.nist.gov
29
cve-2013-3758
enterprise manager
em db control
em plugin
oracle
grid control
remote attack

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

Low

EPSS

0.004

Percentile

75.2%

Unspecified vulnerability in the Enterprise Manager (EM) Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.2 and 12.1.0.3 in Oracle Enterprise Manager Grid Control allows remote attackers to affect integrity via unknown vectors related to Schema Management.

Affected configurations

Nvd
Node
oracleenterprise_managerMatch10.2.0.5
OR
oracleenterprise_managerMatch11.1.0.1
OR
oracleenterprise_manager_database_controlMatch10.2.0.4
OR
oracleenterprise_manager_database_controlMatch10.2.0.5
OR
oracleenterprise_manager_database_controlMatch11.1.0.7
OR
oracleenterprise_manager_database_controlMatch11.2.0.2
OR
oracleenterprise_manager_database_controlMatch11.2.0.3
OR
oracleenterprise_manager_plugin_for_database_controlMatch12.1.0.2
OR
oracleenterprise_manager_plugin_for_database_controlMatch12.1.0.3
VendorProductVersionCPE
oracleenterprise_manager_database_control11.1.0.7cpe:/a:oracle:enterprise_manager_database_control:11.1.0.7:::
oracleenterprise_manager_database_control11.2.0.3cpe:/a:oracle:enterprise_manager_database_control:11.2.0.3:::
oracleenterprise_manager_plugin_for_database_control12.1.0.2cpe:/a:oracle:enterprise_manager_plugin_for_database_control:12.1.0.2:::
oracleenterprise_manager_database_control11.2.0.2cpe:/a:oracle:enterprise_manager_database_control:11.2.0.2:::
oracleenterprise_manager_database_control10.2.0.4cpe:/a:oracle:enterprise_manager_database_control:10.2.0.4:::
oracleenterprise_manager10.2.0.5cpe:/a:oracle:enterprise_manager:10.2.0.5:::
oracleenterprise_manager_plugin_for_database_control12.1.0.3cpe:/a:oracle:enterprise_manager_plugin_for_database_control:12.1.0.3:::
oracleenterprise_manager_database_control10.2.0.5cpe:/a:oracle:enterprise_manager_database_control:10.2.0.5:::
oracleenterprise_manager11.1.0.1cpe:/a:oracle:enterprise_manager:11.1.0.1:::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6

Confidence

Low

EPSS

0.004

Percentile

75.2%