PT-2002-2364 · Oracle · Oracle Configurator

Publicado

2002-04-01

·

Atualizado

2018-09-26

·

CVE-2002-1640

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Configurator versions prior to 11.5.7.17.32 Oracle Configurator versions prior to 11.5.6.16.53
Description The issue allows remote attackers to inject arbitrary web script or HTML, which can lead to cross-site scripting (XSS) attacks. This can be achieved via two methods: (1) using Text Features in the DHTML UI or (2) by manipulating the test parameter to the "oracle.apps.cz.servlet.UiServlet" servlet.
Recommendations For Oracle Configurator versions prior to 11.5.7.17.32, update to version 11.5.7.17.32 or later. For Oracle Configurator versions prior to 11.5.6.16.53, update to version 11.5.6.16.53 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1640

Produtos afetados

Oracle Configurator