Oracle E-Business (July 2014 CPU)

medium Nessus Plugin ID 76596

Synopsis

The remote host has a web application installed that is affected by multiple vulnerabilities.

Description

The version of Oracle E-Business installed on the remote host is missing the July 2014 Critical Patch Update (CPU). It is, therefore, affected by vulnerabilities in the following components :

- Oracle Applications Technology Stack
- Oracle Concurrent Processing
- Oracle Applications Manager
- Oracle iStore
- Oracle Applications Object Library

Solution

Apply the appropriate patch according to the July 2014 Oracle Critical Patch Update advisory.

See Also

http://www.nessus.org/u?77697fb1

Plugin Details

Severity: Medium

ID: 76596

File Name: oracle_e-business_cpu_jul_2014.nasl

Version: 1.12

Type: remote

Family: Misc.

Published: 7/18/2014

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.7

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2014-0224

Vulnerability Information

CPE: cpe:/a:oracle:e-business_suite

Required KB Items: Oracle/E-Business/Version, Oracle/E-Business/patches/installed

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/15/2014

Vulnerability Publication Date: 7/15/2014

Exploitable With

Core Impact

Reference Information

CVE: CVE-2014-0224, CVE-2014-2482, CVE-2014-4213, CVE-2014-4235, CVE-2014-4248

BID: 67899, 68647, 68648, 68651, 68653

CERT: 978508