CVE-2012-1707
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to…
Does this matter?
Lower severity and a low EPSS score (1.43%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.3.0 through 5.3.4, 6.0.1, and 6.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Core-Base, a different vulnerability than CVE-2012-1704.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
- EPSS
- 1.43% probability · 72th percentile
- CISA KEV
- Not listed
- Affected
- oracle/financial services software
- Source
- secalert_us@oracle.com
References
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150Broken Link
- http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/53107Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026953Third Party Advisory, VDB Entry
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150Broken Link
- http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/53107Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1026953Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.