PT-2005-3222 · Oracle · Oracle Forms
Alexander Kornbrust
·
Published
2005-07-17
·
Updated
2017-07-11
·
CVE-2005-2294
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Oracle Forms versions 4.5, 6.0, 6i, and 9i
Description:
The issue allows local users to gain sensitive information, such as credit card numbers, when a large number of records are retrieved by an Oracle form. This occurs because the system stores a copy of the database tables in a world-readable temporary file.
Recommendations:
For Oracle Forms versions 4.5, 6.0, 6i, and 9i, consider restricting access to the temporary files generated by the system to minimize the risk of sensitive information disclosure.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Forms