← All CVEs

CVE-2013-3827

medium · 5

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors related to Java Server Faces or Web Container.

5
CVSS
32.4%
EPSS (exploit prob.)
98th
EPSS percentile
2013-10-16
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

VendorProductAffected versions
oraclefusion_middleware2.1.1
oraclefusion_middleware3.0.1
oraclefusion_middleware3.1.2
oraclefusion_middleware10.3.6
oraclefusion_middleware11.1.2.3.0
oraclefusion_middleware11.1.2.4.0
oraclefusion_middleware12.1.1
oraclefusion_middleware12.1.2.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-3827