VulnerabilityModified
CVE-2016-5601
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows local users to affect confidentiality and integrity via vectors related to CIE Related Components.
MEDIUM 6.3EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows local users to affect confidentiality and integrity via vectors related to CIE Related Components.
- CVSS 3.0
- 6.3 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- oracle/weblogic server
- Source
- secalert_us@oracle.com
References
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/93704
- http://www.securitytracker.com/id/1037052
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/93704
- http://www.securitytracker.com/id/1037052
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.