CVE-2015-4851: Medium severity oracle e-business suite vulnerability
Unspecified vulnerability in the Oracle iSupplier Portal component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to XML input. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to read arbitrary files, cause a denial of service, or conduct SMB Relay attacks via a crafted DTD in an XML request to OAHTML/oramipplpr.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4851?
CVE-2015-4851 is classified as a high severity vulnerability due to its potential impact on confidentiality, integrity, and availability.
How do I fix CVE-2015-4851?
To fix CVE-2015-4851, it is recommended to apply the latest patches provided by Oracle for affected versions of E-Business Suite.
What versions of Oracle E-Business Suite are affected by CVE-2015-4851?
CVE-2015-4851 affects Oracle E-Business Suite versions 12.0.6, 12.1.3, 12.2.3, and 12.2.4.
What types of attacks can exploit CVE-2015-4851?
CVE-2015-4851 can be exploited by remote attackers through vectors related to XML input, potentially leading to unauthorized access or manipulation of data.
Is there a workaround for CVE-2015-4851?
Currently, Oracle recommends applying patches as the primary mitigation for CVE-2015-4851 rather than a workaround.