PT-2011-1412 · Oracle · Empop3Lib+1

Publicado

2011-01-19

·

Atualizado

2018-10-10

·

CVE-2010-3591

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Fusion Middleware versions 10.1.3.4 through 10.1.3.5
Description The issue affects confidentiality, integrity, and availability. It is related to Internal Operations in the Oracle Document Capture component. There are claims that remote attackers can overwrite or delete arbitrary files via a full pathname in the second argument to the DownloadSingleMessageToFile method in the EMPOP3Lib ActiveX component (empop3.dll).
Recommendations For Oracle Fusion Middleware versions 10.1.3.4 and 10.1.3.5, consider restricting access to the EMPOP3Lib ActiveX component (empop3.dll) to minimize the risk of exploitation. As a temporary workaround, avoid using the DownloadSingleMessageToFile method until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-3591

Produtos afetados

Empop3Lib
Oracle Fusion Middleware