Vulnerabilities > Oracle > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-10-01 CVE-2012-5627 Insufficiently Protected Credentials vulnerability in multiple products
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.
network
low complexity
oracle mariadb CWE-522
4.0
2013-07-17 CVE-2013-3825 Information Exposure vulnerability in Oracle Supply Chain products Suite 9.3.1
Unspecified vulnerability in the Oracle Agile Product Collaboration component in Oracle Supply Chain Products Suite 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Folders & Files Attachment.
network
low complexity
oracle CWE-200
4.0
2013-07-17 CVE-2013-3824 Remote Security vulnerability in Oracle Supply Chain products Suite 9.3.1
Unspecified vulnerability in the Oracle Agile Collaboration Framework component in Oracle Supply Chain Products Suite 9.3.1 allows remote authenticated users to affect integrity via unknown vectors related to Manufacturing/Mfg Parts.
network
low complexity
oracle
4.0
2013-07-17 CVE-2013-3823 Information Exposure vulnerability in Oracle Supply Chain products Suite 9.3.1
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.
network
low complexity
oracle CWE-200
4.0
2013-07-17 CVE-2013-3822 Remote Security vulnerability in Oracle Supply Chain products Suite 9.3.1
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1 allows remote attackers to affect integrity via unknown vectors related to Web Client (CS).
network
oracle
4.3
2013-07-17 CVE-2013-3821 Remote Security vulnerability in Oracle Peoplesoft products 8.51/8.52/8.53
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect confidentiality and availability via unknown vectors related to Integration Broker.
network
low complexity
oracle
6.4
2013-07-17 CVE-2013-3820 Remote Security vulnerability in Oracle Peoplesoft products 8.51/8.52/8.53
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect availability via unknown vectors related to Business Interlink.
network
low complexity
oracle
5.0
2013-07-17 CVE-2013-3819 Remote Security vulnerability in Oracle Peoplesoft products 8.51/8.52/8.53
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect confidentiality and availability via unknown vectors related to Mobile Applications.
network
low complexity
oracle
6.4
2013-07-17 CVE-2013-3818 Remote Security vulnerability in Oracle Peoplesoft products 8.51/8.52/8.53
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via unknown vectors related to Portal, a different vulnerability than CVE-2013-2404.
network
oracle
4.3
2013-07-17 CVE-2013-3816 Remote Security vulnerability in Oracle Policy Automation
Unspecified vulnerability in the Oracle Policy Automation component in Oracle Industry Applications 10.2.0, 10.3.0, 10.3.1, 10.4.0, 10.4.1, and 10.4.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Determinations Engine.
network
low complexity
oracle
4.0