Oracle E-Business Multiple Vulnerabilities (October 2014 CPU)

high Nessus Plugin ID 78544

Synopsis

The remote host has a web application installed that is affected by multiple vulnerabilities.

Description

The version of Oracle E-Business installed on the remote host is missing the October 2014 Oracle Critical Patch Update (CPU). It is, therefore, affected by vulnerabilities in the following components :

- Oracle Application Technology Stack
- Oracle Applications Framework
- Oracle Applications Object Library
- Oracle Payments

Solution

Apply the appropriate patch according to the October 2014 Oracle Critical Patch Update advisory.

See Also

http://www.nessus.org/u?1ada40cc

Plugin Details

Severity: High

ID: 78544

File Name: oracle_e-business_cpu_oct_2014.nasl

Version: 1.10

Type: remote

Family: Misc.

Published: 10/17/2014

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.2

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.2

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2014-4278

Vulnerability Information

CPE: cpe:/a:oracle:e-business_suite

Required KB Items: Oracle/E-Business/Version, Oracle/E-Business/patches/installed

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/14/2014

Vulnerability Publication Date: 10/14/2014

Exploitable With

CANVAS (CANVAS)

Reference Information

CVE: CVE-2014-4278, CVE-2014-4281, CVE-2014-4285, CVE-2014-6471, CVE-2014-6472, CVE-2014-6479, CVE-2014-6523, CVE-2014-6539, CVE-2014-6550, CVE-2014-6561

BID: 70445, 70447, 70450, 70454, 70457, 70461, 70466, 70471, 70475, 70485