CVE-2011-3525

critical

Description

Unspecified vulnerability in the Application Express component in Oracle Database Server 3.2 and 4.0 allows remote authenticated users to affect confidentiality, integrity, and availability, related to APEX developer user.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/70799

http://www.securityfocus.com/bid/50197

http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html

http://osvdb.org/76516

Details

Source: Mitre, NVD

Published: 2011-10-18

Updated: 2017-08-29

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Severity: Critical