CVE-2013-3827 : Detail

CVE-2013-3827

58.06%V3
Network
2013-10-16
13h00 +00:00
2016-12-29
17h57 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors related to Java Server Faces or Web Container.

CVE Informations

Related Weaknesses

CWE-ID Weakness Name Source
CWE Other No informations.

Metrics

Metrics Score Severity CVSS Vector Source
V2 5 AV:N/AC:L/Au:N/C:P/I:N/A:N [email protected]

EPSS

EPSS is a scoring model that predicts the likelihood of a vulnerability being exploited.

EPSS Score

The EPSS model produces a probability score between 0 and 1 (0 and 100%). The higher the score, the greater the probability that a vulnerability will be exploited.

EPSS Percentile

The percentile is used to rank CVE according to their EPSS score. For example, a CVE in the 95th percentile according to its EPSS score is more likely to be exploited than 95% of other CVE. Thus, the percentile is used to compare the EPSS score of a CVE with that of other CVE.

Exploit information

Exploit Database EDB-ID : 38802

Publication date : 2013-10-14 22h00 +00:00
Author : Alex Kouzemtchenko
EDB Verified : Yes

source: https://www.securityfocus.com/bid/63052/info Oracle JavaServer Faces is prone to multiple directory-traversal vulnerabilities. Exploiting these issues may allow an attacker to obtain sensitive information that could aid in further attacks. This vulnerability affects the following products and versions: WebLogic Server 10.3.6.0, 12.1.1.0 GlassFish Server 2.1.1, 3.0.1, 3.1.2 JDeveloper 11.1.2.3.0, 11.1.2.4.0, 12.1.2.0.0 http://www.example.com/someApp/javax.faces.resource.../WEB-INF/web.xml.jsf http://www.example.com/someApp/javax.faces.resource./WEB-INF/web.xml.jsf?ln=..

Products Mentioned

Configuraton 0

Oracle>>Fusion_middleware >> Version 2.1.1

Oracle>>Fusion_middleware >> Version 3.0.1

Oracle>>Fusion_middleware >> Version 3.1.2

Oracle>>Fusion_middleware >> Version 10.3.6

Oracle>>Fusion_middleware >> Version 11.1.2.3.0

Oracle>>Fusion_middleware >> Version 11.1.2.4.0

Oracle>>Fusion_middleware >> Version 12.1.1

Oracle>>Fusion_middleware >> Version 12.1.2.0.0

References

http://www.securityfocus.com/bid/63052
Tags : vdb-entry, x_refsource_BID
http://rhn.redhat.com/errata/RHSA-2014-0029.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.kb.cert.org/vuls/id/526012
Tags : third-party-advisory, x_refsource_CERT-VN
http://www.securitytracker.com/id/1029190
Tags : vdb-entry, x_refsource_SECTRACK