Oracle Data Quality and Profiling Client Multiple Vulnerabilities (April 2014 CPU)

medium Nessus Plugin ID 73826

Synopsis

The remote host has software installed that is affected by multiple vulnerabilities.

Description

According to the version of the Oracle Data Quality and Profiling client installed on the remote host, it is affected by multiple unspecified ActiveX control vulnerabilities. By tricking a user into opening a specially crafted document, an attacker may be able to execute arbitrary code.

Solution

Apply the appropriate patch according to the April 2014 Oracle Critical Patch Update advisory.

See Also

https://www.zerodayinitiative.com/advisories/ZDI-14-107/

https://www.zerodayinitiative.com/advisories/ZDI-14-108/

https://www.zerodayinitiative.com/advisories/ZDI-14-109/

https://www.zerodayinitiative.com/advisories/ZDI-14-110/

https://www.zerodayinitiative.com/advisories/ZDI-14-111/

http://www.nessus.org/u?ef1fc2a6

Plugin Details

Severity: Medium

ID: 73826

File Name: oracle_dqpc_april_2014_cpu.nasl

Version: 1.8

Type: local

Agent: windows

Family: Windows

Published: 5/2/2014

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.7

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2014-2418

Vulnerability Information

CPE: cpe:/a:oracle:fusion_middleware

Required KB Items: Oracle/ODQPC/Installed

Exploit Ease: No known exploits are available

Patch Publication Date: 4/15/2014

Vulnerability Publication Date: 4/15/2014

Reference Information

CVE: CVE-2014-2407, CVE-2014-2415, CVE-2014-2416, CVE-2014-2417, CVE-2014-2418

BID: 66836, 66841, 66842, 66844, 66845