[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-3564Date: (C)2010-10-14   (M)2024-02-22


Unspecified vulnerability in the Oracle Communications Messaging Server (Sun Java System Messaging Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Webmail. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that the Kerberos implementation does not properly check AP-REQ requests, which allows attackers to cause a denial of service in the JVM. NOTE: CVE has not investigated the apparent discrepancy between the two vendors regarding the consequences of this issue.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.4
Exploit Score: 10.0
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECUNIA-41972
SECUNIA-42377
BID-43963
ADV-2010-3086
FEDORA-2010-16240
FEDORA-2010-16294
FEDORA-2010-16312
GLSA-201406-32
RHSA-2010:0768
RHSA-2010:0865
SSRT100333
TA10-287A
USN-1010-1
http://support.avaya.com/css/P8/documents/100114327
http://support.avaya.com/css/P8/documents/100123193
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html
http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
oval:org.mitre.oval:def:12398

CPE    1
cpe:/a:oracle:sun_products_suite:7.0
OVAL    8
oval:org.secpod.oval:def:500485
oval:org.secpod.oval:def:201839
oval:org.secpod.oval:def:500489
oval:org.secpod.oval:def:700014
...

© SecPod Technologies