6.4
CVSSv2

CVE-2013-0397

Published: 17/01/2013 Updated: 16/03/2014
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote malicious users to affect confidentiality and integrity via unknown vectors related to Diagnostics.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle e-business suite 12.0.6

oracle e-business suite 12.1.3

oracle e-business suite 11.5.10.2

Exploits

Trustwave SpiderLabs Security Advisory TWSL2012-023: Oracle Application Framework Diagnostic Mode Bypass Vulnerability Published: 1/15/2013 Version: 10 Vendor: Oracle (wwworaclecom) Product: Oracle Application Framework Version affected: 115102, 1206, 1213 Product description: The Oracle Application Framework is a Java library used to ...
The Oracle Application Framework supports diagnostic and developer mode features that are intended to be enabled from developer or administrative interfaces However, any user can manually enable the modes by setting the "OADiagnostic" or "OADeveloperMode" cookies to "1" Versions affected include 115102, 1206, and 1213 ...