CVE-2010-3544
Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect integrity and availability via unknown vectors related to Administration.
Does this matter?
Lower severity and a low EPSS score (2.33%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect integrity and availability via unknown vectors related to Administration. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable source that this is cross-site request forgery (CSRF) that allows remote attackers to stop an instance via the management console.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 2.33% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- oracle/sun products suite
- Source
- secalert_us@oracle.com
References
- http://jvn.jp/en/jp/JVN50133036/index.html
- http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000042.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA10-287A.htmlUS Government Resource
- http://jvn.jp/en/jp/JVN50133036/index.html
- http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000042.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlVendor Advisory
- http://www.us-cert.gov/cas/techalerts/TA10-287A.htmlUS Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.