CVE-2015-4735
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1, and EM DB Control 11.2.0.3 and 11.2.0.4, allows remote attackers to affect confidentiality via vectors…
Does this matter?
Lower severity and a low EPSS score (2.79%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1, and EM DB Control 11.2.0.3 and 11.2.0.4, allows remote attackers to affect confidentiality via vectors related to RAC Management.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.79% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- oracle/enterprise manager database control · oracle/enterprise manager grid control
- Source
- secalert_us@oracle.com
References
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00003.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlPatch, Vendor Advisory
- http://www.securitytracker.com/id/1032918Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00003.htmlThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.htmlPatch, Vendor Advisory
- http://www.securitytracker.com/id/1032918Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.