High severity8.2NVD Advisory· Published Jul 21, 2016· Updated May 6, 2026
CVE-2016-3535
CVE-2016-3535
Description
Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Remote Launch. NOTE: the previous information is from the July 2016 CPU. Oracle has not commented on third-party claims that this issue is a cross-site scripting (XSS) vulnerability, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlnvdPatchVendor Advisory
- www.securityfocus.com/bid/91787nvdThird Party AdvisoryVDB Entry
- www.onapsis.com/blog/oracle-fixes-record-276-vulnerabilities-july-2016nvdThird Party Advisory
- www.securityfocus.com/bid/91845nvd
- www.securitytracker.com/id/1036403nvd
News mentions
0No linked articles in our index yet.