Vulnerabilities > CVE-2013-3781 - Unspecified vulnerability in Oracle Fusion Middleware 8.3.7.0/8.4/8.4.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN oracle
nessus
Summary
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7, 8.4.0, and 8.4.1 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-3776.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Msbulletin
bulletin_id | MS13-061 |
bulletin_url | |
date | 2013-08-13T00:00:00 |
impact | Remote Code Execution |
knowledgebase_id | 2876063 |
knowledgebase_url | |
severity | Critical |
title | Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS13-061.NASL |
description | The version of Microsoft Exchange installed on the remote host uses a version of the Oracle Outside In libraries, which are affected by the following vulnerabilities : - Two unspecified code execution vulnerabilities exist in the WebReady Document Viewing feature of Outlook Web Access. (CVE-2013-2393, CVE-2013-3776) - An unspecified denial of service vulnerability exists in the Data Loss Protection feature. This vulnerability only affects Exchange 2013. (CVE-2013-3781) These vulnerabilities can be exploited when a user views a maliciously crafted file in Outlook Web Access in a browser. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 69326 |
published | 2013-08-14 |
reporter | This script is Copyright (C) 2013-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/69326 |
title | MS13-061: Vulnerabilities in Microsoft Exchange Server Could Allow Remote Code Execution (2876063) |
code |
|
Oval
accepted | 2013-10-14T04:00:11.165-04:00 | ||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||
contributors |
| ||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||
description | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7, 8.4.0, and 8.4.1 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-3776. | ||||||||||||||||||||
family | windows | ||||||||||||||||||||
id | oval:org.mitre.oval:def:18156 | ||||||||||||||||||||
status | accepted | ||||||||||||||||||||
submitted | 2013-08-19T11:51:17 | ||||||||||||||||||||
title | Oracle Outside In Contains Multiple Exploitable Vulnerabilities - CVE-2013-3781 (MS13-061) | ||||||||||||||||||||
version | 6 |
References
- http://jvn.jp/en/jp/JVN07497769/index.html
- http://jvn.jp/en/jp/JVN07497769/index.html
- http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-000070.html
- http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-000070.html
- http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html
- http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html
- http://www.securityfocus.com/bid/61232
- http://www.securityfocus.com/bid/61232
- http://www.securitytracker.com/id/1028801
- http://www.securitytracker.com/id/1028801
- http://www-01.ibm.com/support/docview.wss?uid=swg21660640
- http://www-01.ibm.com/support/docview.wss?uid=swg21660640
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-061
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-061
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18156
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18156