VulnerabilityModified
CVE-2007-5531
Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Database 10.2.0.3, and Enterprise Manager 10.1.0.6, has unknown impact and remote attack vectors, aka EM02.
HIGH 10.0EPSS 3.63%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Database 10.2.0.3, and Enterprise Manager 10.1.0.6, has unknown impact and remote attack vectors, aka EM02.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.63% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- oracle/application server · oracle/database server · oracle/enterprise manager
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=119332677525918&w=2Mailing List, Third Party Advisory
- http://secunia.com/advisories/27251Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/27409Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2007-092913.htmlVendor Advisory
- http://www.securitytracker.com/id?1018823Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-290A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/3524Permissions Required
- http://www.vupen.com/english/advisories/2007/3626Permissions Required
- http://marc.info/?l=bugtraq&m=119332677525918&w=2Mailing List, Third Party Advisory
- http://secunia.com/advisories/27251Third Party Advisory, Vendor Advisory
- http://secunia.com/advisories/27409Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpuoct2007-092913.htmlVendor Advisory
- http://www.securitytracker.com/id?1018823Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-290A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/3524Permissions Required
- http://www.vupen.com/english/advisories/2007/3626Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.