CVE-2015-1793: Medium severity Oracle Supply Chain Products Suite vulnerability
Published Jul 9, 2015
·Updated
The X509verifycert function in crypto/x509/x509vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
Affected Software
10 affected components
Oracle Supply Chain Products Suite=6.1.2.2
Oracle Supply Chain Products Suite=6.1.3.0
Oracle Supply Chain Products Suite=6.2.0
Oracle JD Edwards EnterpriseOne Tools=9.1
Oracle JD Edwards EnterpriseOne Tools=9.2
OpenSSL OpenSSL=1.0.1n
OpenSSL OpenSSL=1.0.1o
OpenSSL OpenSSL=1.0.2b
OpenSSL OpenSSL=1.0.2c
Oracle Opus 10g Ethernet Switch Family<=2.0.0.6
Remediation
Event History
Jul 9, 2015
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1793?
CVE-2015-1793 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-1793?
To fix CVE-2015-1793, update your OpenSSL version to 1.0.2d or later.
3
What systems are affected by CVE-2015-1793?
CVE-2015-1793 affects specific versions of OpenSSL and Oracle Supply Chain Products Suite.
4
Can CVE-2015-1793 lead to a Certification Authority spoofing?
Yes, CVE-2015-1793 allows remote attackers to spoof a Certification Authority role.
5
Is CVE-2015-1793 exploitable remotely?
Yes, CVE-2015-1793 can be exploited remotely by attackers.