CVE-2016-0456 - CVE House
Back to Database
Status published Medium CVE-2016-0456

Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite...

Vulnerability Description

Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote attackers to affect confidentiality via vectors related to REST Framework, a different vulnerability than CVE-2016-0457. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this issue is an XML External Entity (XXE) vulnerability, which allows remote attackers to read arbitrary files, cause a denial of service, conduct server-side request forgery (SSRF) attacks, or conduct SMB Relay attacks via a crafted DTD in an XML request to OA_HTML/copxmllcmservicecontroller.js.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-0456

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

e-business suite
Vulnerable Versions:
12.1, 12.2

Timeline

Official Publish: January 21st, 2016
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.