SB2016072011 - Privilege escalation in Oracle Secure Global Desktop 



SB2016072011 - Privilege escalation in Oracle Secure Global Desktop

Published: July 20, 2016 Updated: November 22, 2018

Security Bulletin ID SB2016072011
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Privilege escalation (CVE-ID: CVE-2016-3613)

The vulnerability allows a remote attacker to gain elevated privileges.

The vulnerability exists in Oracle Secure Global Desktop. A remote user can gain elevated privileges by exploiting a flaw in the Oracle Secure Global Desktop OpenSSL component.

Successful exploitation of this vulnerability may result in user access with elevated privileges on the target system.


Remediation

Install update from vendor's website.