Oracle E-Business Multiple Vulnerabilities (July 2015 CPU)

medium Nessus Plugin ID 84766

Synopsis

The remote host has a web application installed that is affected by multiple vulnerabilities.

Description

The version of Oracle E-Business installed on the remote host is missing the July 2015 Oracle Critical Patch Update (CPU). It is, therefore, affected by affected by vulnerabilities in the following components :

- Oracle Application Object Library (CVE-2015-2618)
- Oracle Application Object Library (CVE-2015-4739)
- Oracle Applications DBA (CVE-2015-4743)
- Oracle Applications Framework (CVE-2015-1926)
- Oracle Applications Framework (CVE-2015-2610)
- Oracle Applications Framework (CVE-2015-2615)
- Oracle Applications Framework (CVE-2015-4741)
- Oracle Applications Manager (CVE-2015-4765)
- Oracle HTTP Server (CVE-2014-3571)
- Oracle Marketing (CVE-2015-2652)
- Oracle Sourcing (CVE-2015-4728)
- Oracle Web Applications Desktop Integrator (CVE-2015-2645)
- Technology stack (CVE-2015-2630)

Solution

Apply the appropriate patch according to the July 2015 Oracle Critical Patch Update advisory.

See Also

http://www.nessus.org/u?d18c2a85

Plugin Details

Severity: Medium

ID: 84766

File Name: oracle_e-business_cpu_jul_2015.nasl

Version: 1.9

Type: remote

Family: Misc.

Published: 7/15/2015

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2015-1926

Vulnerability Information

CPE: cpe:/a:oracle:e-business_suite

Required KB Items: Oracle/E-Business/Version, Oracle/E-Business/patches/installed

Exploit Ease: No known exploits are available

Patch Publication Date: 7/14/2015

Vulnerability Publication Date: 7/14/2015

Reference Information

CVE: CVE-2014-3571, CVE-2015-1926, CVE-2015-2610, CVE-2015-2615, CVE-2015-2618, CVE-2015-2630, CVE-2015-2645, CVE-2015-2652, CVE-2015-4728, CVE-2015-4739, CVE-2015-4741, CVE-2015-4743, CVE-2015-4765

BID: 71937, 75772, 75782, 75783, 75786, 75787, 75788, 75789, 75790, 75791, 75792, 75795, 75860