Oracle E-Business Multiple Vulnerabilities (January 2015 CPU)

medium Nessus Plugin ID 80952

Synopsis

The remote host has a web application installed that is affected by multiple vulnerabilities.

Description

The version of Oracle E-Business installed on the remote host is missing the January 2015 Oracle Critical Patch Update (CPU). It is, therefore, affected by vulnerabilities in the following components :

- Oracle Application Object Library
- Oracle Applications DBA
- Oracle Applications DBA
- Oracle Applications Framework
- Oracle Customer Intelligence
- Oracle Customer Interaction History
- Oracle HCM Configuration Workbench
- Oracle Marketing
- Oracle Telecommunications Billing Integrator
- Oracle Web Applications Desktop Integrator

Solution

Apply the appropriate patch according to the January 2015 Oracle Critical Patch Update advisory.

See Also

http://www.nessus.org/u?75c6cafb

Plugin Details

Severity: Medium

ID: 80952

File Name: oracle_e-business_cpu_jan_2015.nasl

Version: 1.10

Type: remote

Family: Misc.

Published: 1/23/2015

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2014-6583

Vulnerability Information

CPE: cpe:/a:oracle:e-business_suite

Required KB Items: Oracle/E-Business/Version, Oracle/E-Business/patches/installed

Exploit Ease: No known exploits are available

Patch Publication Date: 1/20/2015

Vulnerability Publication Date: 1/20/2015

Reference Information

CVE: CVE-2014-6525, CVE-2014-6556, CVE-2014-6572, CVE-2014-6581, CVE-2014-6582, CVE-2014-6583, CVE-2015-0380, CVE-2015-0393, CVE-2015-0404, CVE-2015-0415

BID: 72222, 72224, 72228, 72230, 72231, 72232, 72233, 72236, 72239, 72241