CVE-2014-6477: Infoleak
Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4293, CVE-2014-4296, CVE-2014-4297, CVE-2014-4310, and CVE-2014-6547. NOTE: this issue was originally mapped to CVE-2014-4301, but CVE-2014-4301 is for an unrelated vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6477?
CVE-2014-6477 has a medium severity rating due to its potential impact on confidentiality.
How do I fix CVE-2014-6477?
To fix CVE-2014-6477, apply the security patches provided by Oracle for the affected database versions.
Which Oracle Database versions are affected by CVE-2014-6477?
CVE-2014-6477 affects Oracle Database versions 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2.
Who can exploit CVE-2014-6477?
CVE-2014-6477 can be exploited by remote authenticated users.
What impact does CVE-2014-6477 have?
CVE-2014-6477 can impact the confidentiality of data within the affected Oracle Database instances.