PT-2009-1274 · Oracle · Oracle Applications Framework+1
Publicado
2009-01-14
·
Atualizado
2018-10-11
·
CVE-2008-5446
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle E-Business Suite versions 11.5.10 CU2 through 11.5.10 CU2
Oracle E-Business Suite versions 12.0.6 through 12.0.6
Description
The issue affects confidentiality and can be exploited by remote authenticated users via unknown vectors. There are claims that this issue is related to unrestricted guest access to the "About Us Page" in the Oracle Applications Framework (OAF), which allows attackers to obtain sensitive system and application environment information.
Recommendations
For Oracle E-Business Suite version 11.5.10 CU2, restrict access to the "About Us Page" in the Oracle Applications Framework (OAF) to prevent unauthorized access to sensitive information.
For Oracle E-Business Suite version 12.0.6, restrict access to the "About Us Page" in the Oracle Applications Framework (OAF) to prevent unauthorized access to sensitive information.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Applications Framework
Oracle E-Business Suite