Oracle Oracle Enterprise Manager Grid Control Remote EMCTL Vulnerability
12 Apr. 2012
Summary
Unspecified vulnerability in the EMCTL component in Oracle Database Server and Oracle Enterprise Manager Grid Control allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
Vulnerable Systems:
*Oracle Database Server 11.1.0.7
*Oracle Enterprise Manager Grid Control 10.1.0.6
*Oracle Enterprise Manager Grid Control 10.2.0.5
*Oracle Enterprise Manager Grid Control 11.1.0.1
Oracle Oracle Enterprise Manager Grid Control is prone to a remote vulnerability in EMCTL. The vulnerability can be exploited over the 'HTTP' protocol.
Vendor Status:
Oracle as issued an update for this vulnerablity
Disclosure Timeline:
2011-July-19 Rev 1. Initial Release
2011-July-19 Rev 2. Modified Credit Statement and modified Notes in Oracle Sun Products Risk Matrix.
2011-July-21 Rev 3. Pete Finnigan added to the In-Depth Credit Statement.
2011-July-22 Rev 4. Andy Davis added to the Credit Statement.
2011-August-2 Rev 5. Modified supported versions affected for PeopleSoft Enterprise PeopleTools for CVE-2011-2275, CVE-2011-2280 and CVE-2011-2274.
2011-August-19 Rev 6. Modified supported versions affected for PeopleSoft Enterprise PeopleTools and Oracle VM VirtualBox.
2011-December-15 Rev 7. Updated the CVSS score and note for CVE-2011-1511.