8.2

CVE-2016-5491

Unspecified vulnerability in the Oracle Commerce Service Center component in Oracle Commerce 10.0.3.5 and 10.2.0.5 allows remote attackers to affect confidentiality and integrity via unknown vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Commerce Service Center Version 10.0.3.5
Oracle ≫ Commerce Service Center Version 10.2.0.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.43% 0.694
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.2 2.8 4.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
Patch
Vendor Advisory
http://www.securityfocus.com/bid/93667