Information disclosure in Oracle products - CVE-2016-0635
Published: July 21, 2016 / Updated: January 24, 2020
Vulnerability identifier: #VU193
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0635
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in Primavera P6 Enterprise Project Portfolio Management Web Access component. A remote authenticated attacker can gain elevated privileges by exploiting a flaw in the Primavera P6 Enterprise Project Portfolio Management Web access component.
Successful exploitation of this vulnerability may result in disclosure of system information
The vulnerability exists in Primavera P6 Enterprise Project Portfolio Management Web Access component. A remote authenticated attacker can gain elevated privileges by exploiting a flaw in the Primavera P6 Enterprise Project Portfolio Management Web access component.
Successful exploitation of this vulnerability may result in disclosure of system information
Affected software
Oracle Health Sciences Information Manager
Oracle Healthcare Master Person Index
Oracle Retail Order Broker
Oracle Financial Services Analytical Applications Infrastructure
Oracle Insurance Rules Palette
Primavera Contract Management PCM web services
Oracle Commerce Guided Search
Primavera P6 Enterprise Project Portfolio Management
Oracle Agile PLM Framework
Oracle Insurance Policy Administration
Oracle Insurance Calculation Engine
Oracle Documaker
Oracle Enterprise Manager Ops Center
Oracle Retail Integration Bus
Tape Library ACSLS
Oracle Communications Converged Application Server
Oracle Healthcare Master Person Index
Oracle Retail Order Broker
Oracle Financial Services Analytical Applications Infrastructure
Oracle Insurance Rules Palette
Primavera Contract Management PCM web services
Oracle Commerce Guided Search
Primavera P6 Enterprise Project Portfolio Management
Oracle Agile PLM Framework
Oracle Insurance Policy Administration
Oracle Insurance Calculation Engine
Oracle Documaker
Oracle Enterprise Manager Ops Center
Oracle Retail Integration Bus
Tape Library ACSLS
Oracle Communications Converged Application Server
How to mitigate CVE-2016-0635
The vendor has issued a fix as part of the July 2016 Oracle Critical Patch Update.
Oracle Communications Converged Application Server - update to 7.0.0.1