Vulnerabilities > CVE-2014-4239 - Remote Security vulnerability in Oracle Solaris
Attack vector
NETWORK Attack complexity
LOW Privileges required
SINGLE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Common Agent Container (Cacao).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 | |
OS | 3 |
Nessus
NASL family Solaris Local Security Checks NASL id SOLARIS10_123893.NASL description Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. This plugin has been deprecated and either replaced with individual 123893 patch-revision plugins, or deemed non-security related. last seen 2019-02-21 modified 2018-07-30 plugin id 73908 published 2014-05-08 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=73908 title Solaris 10 (sparc) : 123893-81 (deprecated) NASL family Solaris Local Security Checks NASL id SOLARIS9_123893.NASL description Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. last seen 2020-06-01 modified 2020-06-02 plugin id 73911 published 2014-05-08 reporter This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/73911 title Solaris 9 (sparc) : 123893-81 NASL family Solaris Local Security Checks NASL id SOLARIS10_X86_123896-79.NASL description Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. last seen 2020-06-01 modified 2020-06-02 plugin id 107897 published 2018-03-12 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/107897 title Solaris 10 (x86) : 123896-79 NASL family Solaris Local Security Checks NASL id SOLARIS9_X86_123896.NASL description Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. last seen 2020-06-01 modified 2020-06-02 plugin id 73912 published 2014-05-08 reporter This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/73912 title Solaris 9 (x86) : 123896-81 NASL family Solaris Local Security Checks NASL id SOLARIS10_X86_123896.NASL description Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. This plugin has been deprecated and either replaced with individual 123896 patch-revision plugins, or deemed non-security related. last seen 2019-02-21 modified 2018-07-30 plugin id 73909 published 2014-05-08 reporter Tenable source https://www.tenable.com/plugins/index.php?view=single&id=73909 title Solaris 10 (x86) : 123896-81 (deprecated) NASL family Solaris Local Security Checks NASL id SOLARIS8_123893.NASL description Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. last seen 2020-06-01 modified 2020-06-02 plugin id 73910 published 2014-05-08 reporter This script is Copyright (C) 2014-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/73910 title Solaris 8 (sparc) : 123893-81 NASL family Solaris Local Security Checks NASL id SOLARIS10_123893-79.NASL description Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. last seen 2020-06-01 modified 2020-06-02 plugin id 107394 published 2018-03-12 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/107394 title Solaris 10 (sparc) : 123893-79 NASL family Solaris Local Security Checks NASL id SOLARIS10_X86_123896-77.NASL description Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. last seen 2020-06-01 modified 2020-06-02 plugin id 107896 published 2018-03-12 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/107896 title Solaris 10 (x86) : 123896-77 NASL family Solaris Local Security Checks NASL id SOLARIS10_123893-77.NASL description Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. last seen 2020-06-01 modified 2020-06-02 plugin id 107393 published 2018-03-12 reporter This script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/107393 title Solaris 10 (sparc) : 123893-77 NASL family Solaris Local Security Checks NASL id SOLARIS_JUL2014_SRU11_1_19_6_0.NASL description This Solaris system is missing necessary patches to address a critical security update : - Vulnerability in the Solaris component of Oracle Enterprise Manager Grid Control (subcomponent: Common Agent Container (Cacao)). Supported versions that are affected are 2.3.1.0, 2.3.1.1, 2.3.1.2, 2.4.0.0, 2.4.1.0 and 2.4.2.0. Easily exploitable vulnerability allows successful authenticated network attacks via SSL/TLS. Successful attack of this vulnerability can result in unauthorized read access to a subset of Solaris accessible data. Note: Applies only when Cacao is running on Solaris platform. (CVE-2014-4239) last seen 2020-06-01 modified 2020-06-02 plugin id 76821 published 2014-07-26 reporter This script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof. source https://www.tenable.com/plugins/nessus/76821 title Oracle Solaris Critical Patch Update : jul2014_SRU11_1_19_6_0
References
- http://seclists.org/fulldisclosure/2014/Dec/23
- http://secunia.com/advisories/59504
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
- http://www.securityfocus.com/archive/1/534161/100/0/threaded
- http://www.securityfocus.com/bid/68631
- http://www.securitytracker.com/id/1030580
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94569