PT-2002-2364 · Oracle · Oracle Configurator
Published
2002-04-01
·
Updated
2018-09-26
·
CVE-2002-1640
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Configurator versions prior to 11.5.7.17.32
Oracle Configurator versions prior to 11.5.6.16.53
Description
The issue allows remote attackers to inject arbitrary web script or HTML, which can lead to cross-site scripting (XSS) attacks. This can be achieved via two methods: (1) using Text Features in the DHTML UI or (2) by manipulating the
test parameter to the "oracle.apps.cz.servlet.UiServlet" servlet.Recommendations
For Oracle Configurator versions prior to 11.5.7.17.32, update to version 11.5.7.17.32 or later.
For Oracle Configurator versions prior to 11.5.6.16.53, update to version 11.5.6.16.53 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Configurator