PT-2006-1349 · Oracle · Oracle Application Server
Alexander Kornbrust
·
Publicado
2006-01-18
·
Atualizado
2018-10-19
·
CVE-2006-0275
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Application Server version 9.0.4.2
Description
The issue is related to directory traversal, allowing the reading of portions of arbitrary XML files via the
customize parameter. This enables an attacker to access sensitive information.Recommendations
For Oracle Application Server version 9.0.4.2, consider restricting access to the
customize parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the customize parameter in sensitive operations until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Application Server