First published: Wed Jul 17 2013(Updated: )
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Logging. NOTE: the previous information is from the July 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to storage of credentials in the (1) FND_LOG_MESSAGES database table or (2) log files by "native login pages."
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle E-Business Suite | =11.5.10.2 | |
Oracle E-Business Suite | =12.0.6 | |
Oracle E-Business Suite | =12.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-3749 is considered to be moderate due to its potential impact on confidentiality in Oracle E-Business Suite.
To fix CVE-2013-3749, you should apply the latest security patches provided by Oracle for the affected versions of the E-Business Suite.
CVE-2013-3749 affects users of Oracle E-Business Suite versions 11.5.10.2, 12.0.6, and 12.1.3.
Yes, CVE-2013-3749 can be exploited by remote authenticated users affecting the confidentiality of the application.
CVE-2013-3749 was disclosed as part of the July 2013 Critical Patch Update by Oracle.