Information disclosure in Oracle products - CVE-2016-0635

 

Information disclosure in Oracle products - CVE-2016-0635

Published: July 21, 2016 / Updated: January 24, 2020


Vulnerability identifier: #VU193
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0635
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists in Primavera P6 Enterprise Project Portfolio Management Web Access component. A remote authenticated attacker can gain elevated privileges by exploiting a flaw in the Primavera P6 Enterprise Project Portfolio Management Web access component.

Successful exploitation of this vulnerability may result in disclosure of system information

Affected software

Oracle Health Sciences Information Manager
Oracle Healthcare Master Person Index
Oracle Retail Order Broker
Oracle Financial Services Analytical Applications Infrastructure
Oracle Insurance Rules Palette
Primavera Contract Management PCM web services
Oracle Commerce Guided Search
Primavera P6 Enterprise Project Portfolio Management
Oracle Agile PLM Framework
Oracle Insurance Policy Administration
Oracle Insurance Calculation Engine
Oracle Documaker
Oracle Enterprise Manager Ops Center
Oracle Retail Integration Bus
Tape Library ACSLS
Oracle Communications Converged Application Server

How to mitigate CVE-2016-0635

The vendor has issued a fix as part of the July 2016 Oracle Critical Patch Update.

Oracle Communications Converged Application Server - update to 7.0.0.1

External References

Related Security Bulletins