PT-2006-1349 · Oracle · Oracle Application Server

Alexander Kornbrust

·

Published

2006-01-18

·

Updated

2018-10-19

·

CVE-2006-0275

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Application Server version 9.0.4.2
Description The issue is related to directory traversal, allowing the reading of portions of arbitrary XML files via the customize parameter. This enables an attacker to access sensitive information.
Recommendations For Oracle Application Server version 9.0.4.2, consider restricting access to the customize parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the customize parameter in sensitive operations until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0275

Affected Products

Oracle Application Server