PT-2002-2363 · Oracle · Oracle Configurator
Published
2002-04-01
·
Updated
2018-09-26
·
CVE-2002-1639
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Configurator versions prior to 11.5.7.17.32
Oracle Configurator versions prior to 11.5.6.16.53
Description
The issue allows remote attackers to obtain sensitive information by sending a request to the "oracle.apps.cz.servlet.UiServlet" servlet with the
test parameter set to "version" or "host".Recommendations
For versions prior to 11.5.7.17.32, update to version 11.5.7.17.32 or later.
For versions prior to 11.5.6.16.53, update to version 11.5.6.16.53 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Configurator