Privilege escalation in Oracle Enterprise Manager Ops Center - CVE-2016-6814

 

Privilege escalation in Oracle Enterprise Manager Ops Center - CVE-2016-6814

Published: October 20, 2017


Vulnerability identifier: #VU8911
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-6814
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain elevated privileges.

The weakness exists due to a flaw in the Oracle Enterprise Manager Ops Center Networking (Apache Groovy) component. A remote attacker can escalate his privileges on the target system.

Affected software

Oracle Enterprise Manager Ops Center
Gentoo Linux
Fedora
IBM Cloud Pak System
Oracle Agile PLM MCAD Connector
Oracle Utilities Framework
MobileFirst Platform
Oracle WebCenter Sites
groovy18
groovy
IBM Spectrum Control
Oracle Communications Unified Inventory Management
IBM Cloud Application Performance Management (APM)

How to mitigate CVE-2016-6814

Install update from vendor's website.

IBM Cloud Pak System - update to 2.3.3.6
groovy18 - addressed in versions 1.8.9-28.fc24, 1.8.9-28.fc25, 1.8.9-28.fc26
groovy - addressed in versions 2.4.5-8.fc24, 2.4.5-10.fc25
IBM Spectrum Control - update to 5.4.10
Oracle Communications Unified Inventory Management - update to 7.4.0
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.20

External References

Related Security Bulletins