PT-2013-3177 · Oracle · Oracle Auto Service Request

Larry W. Cashdollar

·

Publicado

2013-03-18

·

Atualizado

2013-10-11

·

CVE-2013-1495

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Auto Service Request versions prior to 4.3.2
Description The issue allows local users to modify arbitrary files via a symlink attack on a predictable filename in /tmp. This is related to the asr in Oracle Auto Service Request in Oracle Support Tools.
Recommendations For versions prior to 4.3.2, update to version 4.3.2 or later to resolve the issue.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-1495

Produtos afetados

Oracle Auto Service Request