Lucene search

K
cve[email protected]CVE-2014-6477
HistoryNov 23, 2014 - 7:59 p.m.

CVE-2014-6477

2014-11-2319:59:00
CWE-200
web.nvd.nist.gov
40
cve-2014-6477
oracle database
jpublisher
vulnerability
confidentiality
remote authenticated users
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:C/I:N/A:N

5.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.8%

Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4293, CVE-2014-4296, CVE-2014-4297, CVE-2014-4310, and CVE-2014-6547. NOTE: this issue was originally mapped to CVE-2014-4301, but CVE-2014-4301 is for an unrelated vulnerability.

Affected configurations

NVD
Node
oracledatabase_serverMatch11.1.0.7
OR
oracledatabase_serverMatch11.2.0.3
OR
oracledatabase_serverMatch11.2.0.4
OR
oracledatabase_serverMatch12.1.0.1
OR
oracledatabase_serverMatch12.1.0.2

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:C/I:N/A:N

5.6 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.8%