CVE-2011-0794
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5.0 allows local users to affect confidentiality, integrity, and availability, related to File ID SDK.
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5.0 allows local users to affect confidentiality, integrity, and availability, related to File ID SDK. NOTE: the previous information was obtained from the April 2011 CPU. Oracle has not commented on claims from a reliable third party that this issue is in (a) sccut.dll or (b) libsc_ut.so in Outside In 8.3.5.x through 8.3.5.5684, as used when using the CAB file identification functionality to parse OneNote (.onepkg) files and other formats.
- CVSS 2.0
- 4.4 MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Affected
- oracle/fusion middleware
- Source
- secalert_us@oracle.com
References
- http://secunia.com/advisories/44295Vendor Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csa
- http://www-01.ibm.com/support/docview.wss?uid=swg21660640
- http://www.kb.cert.org/vuls/id/520721US Government Resource
- http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=7009213&sliceId=1&docTypeID=DT_TID_1_1&dialogID=268451045&stateId=0%200%20268449309
- http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/47437
- http://secunia.com/advisories/44295Vendor Advisory
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20111026-csa
- http://www-01.ibm.com/support/docview.wss?uid=swg21660640
- http://www.kb.cert.org/vuls/id/520721US Government Resource
- http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=7009213&sliceId=1&docTypeID=DT_TID_1_1&dialogID=268451045&stateId=0%200%20268449309
- http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/47437
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.