Oracle E-Business (January 2014 CPU)

Medium Nessus Plugin ID 72009


The remote host has a web application installed that is affected by multiple vulnerabilities.


The version of Oracle E-Business installed on the remote host is missing the January 2014 Critical Patch Update (CPU). It is, therefore, affected by vulnerabilities in the following components :

- Oracle Payroll
- Oracle Application Object Library
- Oracle Applications Framework


Apply the appropriate patch according to the January 2014 Oracle Critical Patch Update advisory.

See Also

Plugin Details

Severity: Medium

ID: 72009

File Name: oracle_e-business_cpu_jan_2014.nasl

Version: $Revision: 1.5 $

Type: local

Family: Misc.

Published: 2014/01/17

Modified: 2014/08/08

Dependencies: 70177

Risk Information

Risk Factor: Medium


Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:e-business_suite

Required KB Items: Oracle/E-Business/Version, Oracle/E-Business/patches/installed

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2014/01/14

Vulnerability Publication Date: 2014/01/14

Reference Information

CVE: CVE-2013-5874, CVE-2013-5890, CVE-2014-0366, CVE-2014-0398

BID: 64816, 64818, 64828, 64833

OSVDB: 102090, 102091, 102104, 102105