PT-2005-3285 · Oracle · Oracle Reports

Alexander Kornbrust

·

Published

2005-07-26

·

Updated

2018-10-19

·

CVE-2005-2371

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Reports versions 6.0, 6i, 9i, 10g
Description A directory traversal issue allows remote attackers to overwrite arbitrary files by manipulating the desname parameter with sequences such as "..", Windows drive letters (e.g., "C:"), or absolute paths.
Recommendations For Oracle Reports versions 6.0, 6i, 9i, 10g, consider applying the fix provided in CPU Jan 2006, which likely addresses this issue.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-2371

Affected Products

Oracle Reports