PT-2003-2070 · Oracle · Report Review Agent+4
Stephen Kost
·
Published
2003-12-31
·
Updated
2017-07-11
·
CVE-2003-1116
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle E-Business Suite versions 10.7, 11.0, 11.5.1 through 11.5.8
Description
The issue allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener. This is due to a flaw in the communications protocol for the Report Review Agent (RRA), also known as the FND File Server (FNDFS) program.
Recommendations
For Oracle E-Business Suite versions 10.7, 11.0, and 11.5.1 through 11.5.8, consider restricting access to the TNS Listener to minimize the risk of exploitation.
As a temporary workaround, restrict the use of the RRA protocol until a patch is available.
Avoid using the vulnerable protocol to access sensitive information from the Oracle Applications Concurrent Manager until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fnd File Server
Oracle Applications Concurrent Manager
Oracle E-Business Suite
Report Review Agent
Tns Listener