PT-2002-2364 · Oracle · Oracle Configurator

Published

2002-04-01

·

Updated

2018-09-26

·

CVE-2002-1640

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Configurator versions prior to 11.5.7.17.32 Oracle Configurator versions prior to 11.5.6.16.53
Description The issue allows remote attackers to inject arbitrary web script or HTML, which can lead to cross-site scripting (XSS) attacks. This can be achieved via two methods: (1) using Text Features in the DHTML UI or (2) by manipulating the test parameter to the "oracle.apps.cz.servlet.UiServlet" servlet.
Recommendations For Oracle Configurator versions prior to 11.5.7.17.32, update to version 11.5.7.17.32 or later. For Oracle Configurator versions prior to 11.5.6.16.53, update to version 11.5.6.16.53 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1640

Affected Products

Oracle Configurator