Vulnerabilities > Oracle > Supply Chain Products Suite > 6.1.3.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2015-07-09 | CVE-2015-1793 | 7PK - Security Features vulnerability in multiple products The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate. | 6.5 |
2015-04-16 | CVE-2015-0490 | Remote Security vulnerability in Oracle Supply Chain products Suite 6.1.3.0 Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to BAS - Base Component. network oracle | 4.9 |