IM
IronMonkey Threat Research

CVE-2010-3591 HIGH

Published: 2011-01-19 | Last Modified: 2026-06-16 | Status: Modified

Description

Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Internal Operations. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can overwrite or delete arbitrary files via a full pathname in the second argument to the DownloadSingleMessageToFile method in the EMPOP3Lib ActiveX component (empop3.dll).

Additional Descriptions (1)

Vulnerabilidad sin especificar en el componente Oracle Document Capture de Oracle Fusion Middleware 10.1.3.4 y 10.1.3.5 permite a atacantes remotos afectar la confidencialidad, integridad y disponibilidad a través de vectores desconocidos relacionados con operaciones internas.

CVSS Metrics

Base Score: 9.3 (HIGH)

AV:N/AC:M/Au:N/C:C/I:C/A:C

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
oracle fusion_middleware 10.1.3.4 <built-in method update of dict object at 0x72a9a23a3440> Application
oracle fusion_middleware 10.1.3.5 <built-in method update of dict object at 0x72a9a23a27c0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:oracle:fusion_middleware:10.1.3.4:*:*:*:*:*:*:*
Yes cpe:2.3:a:oracle:fusion_middleware:10.1.3.5:*:*:*:*:*:*:*

References

Notification
Message here