Vulnerabilities > CVE-2010-3595 - Unspecified vulnerability in Oracle Fusion Middleware 10.1.3.4/10.1.3.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality via unknown vectors related to Import Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can read arbitrary files via a full pathname in the first argument to the ImportBodyText method in the EasyMail ActiveX control (emsmtp.dll).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | Oracle Document Capture Insecure READ Method. CVE-2010-3595. Remote exploit for windows platform |
file | exploits/windows/remote/16056.txt |
id | EDB-ID:16056 |
last seen | 2016-02-01 |
modified | 2011-01-26 |
platform | windows |
port | |
published | 2011-01-26 |
reporter | Alexey Sintsov |
source | https://www.exploit-db.com/download/16056/ |
title | Oracle Document Capture Insecure READ Method |
type | remote |
Nessus
NASL family | Windows |
NASL id | ORACLE_DOCUMENT_CAPTURE_ACTIVEX.NASL |
description | The Oracle Document Capture client installed on the remote host is potentially affected by multiple vulnerabilities : - An unspecified vulnerability exists in the Import Export utility. An attacker can exploit this to affect integrity. (CVE-2010-3598) - An information disclosure vulnerability exists related to the EasyMail ActiveX control. (CVE-2010-3595) - Insecure methods in the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 51873 |
published | 2011-02-04 |
reporter | This script is Copyright (C) 2011-2018 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/51873 |
title | Oracle Document Capture Multiple Vulnerabilities |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/97872/DSECRG-11-007.txt |
id | PACKETSTORM:97872 |
last seen | 2016-12-05 |
published | 2011-01-25 |
reporter | Sh2kerr |
source | https://packetstormsecurity.com/files/97872/Oracle-Document-Capture-Insecure-READ-Method.html |
title | Oracle Document Capture Insecure READ Method |
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:70623 |
last seen | 2017-11-19 |
modified | 2014-07-01 |
published | 2014-07-01 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-70623 |
title | Oracle Document Capture Insecure READ Method |
References
- http://dsecrg.com/pages/vul/show.php?id=307
- http://dsecrg.com/pages/vul/show.php?id=307
- http://secunia.com/advisories/42976
- http://secunia.com/advisories/42976
- http://www.exploit-db.com/exploits/16056
- http://www.exploit-db.com/exploits/16056
- http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html
- http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html
- http://www.securityfocus.com/archive/1/515957/100/0/threaded
- http://www.securityfocus.com/archive/1/515957/100/0/threaded
- http://www.securityfocus.com/bid/45849
- http://www.securityfocus.com/bid/45849
- http://www.securitytracker.com/id?1024981
- http://www.securitytracker.com/id?1024981
- http://www.vupen.com/english/advisories/2011/0143
- http://www.vupen.com/english/advisories/2011/0143
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64770
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64770