Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-3542. PoCs published by SecuriTeam.
AI-analyzed exploit summary This exploit demonstrates an XXE vulnerability in Oracle Knowledge Management, leading to remote code execution by exfiltrating sensitive files (e.g., custom.xml) and decrypting database credentials. The attack involves setting up a malicious XXE server and a gopher listener to extract and decrypt credentials for further exploitation.
Description
Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote administrators to affect confidentiality and integrity via unknown vectors.
Exploits (1)
This exploit demonstrates an XXE vulnerability in Oracle Knowledge Management, leading to remote code execution by exfiltrating sensitive files (e.g., custom.xml) and decrypting database credentials. The attack involves setting up a malicious XXE server and a gopher listener to extract and decrypt credentials for further exploitation.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N