PT-2006-1349 · Oracle · Oracle Application Server
Alexander Kornbrust
·
Published
2006-01-18
·
Updated
2018-10-19
·
CVE-2006-0275
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Application Server version 9.0.4.2
Description
The issue is related to directory traversal, allowing the reading of portions of arbitrary XML files via the
customize parameter. This enables an attacker to access sensitive information.Recommendations
For Oracle Application Server version 9.0.4.2, consider restricting access to the
customize parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the customize parameter in sensitive operations until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Application Server