PT-2007-5097 · Oracle · Oracle Configurator+4

Published

2007-07-18

·

Updated

2018-10-15

·

CVE-2007-3866

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Oracle E-Business Suite versions 11.5.10CU2 through 12.0.1
Description: The issue affects Oracle E-Business Suite, allowing remote attackers to have an unknown impact. This is achieved through various components, including Oracle Configurator, Oracle iExpenses, Oracle Application Object Library, and specific modules in Oracle Payables.
Recommendations: For Oracle E-Business Suite version 11.5.10CU2, update to a version that addresses the issue. For Oracle E-Business Suite version 12.0.1, apply the necessary patches or updates to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable components, such as Oracle Configurator, Oracle iExpenses, and Oracle Application Object Library, until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3866

Affected Products

Oracle Application Object Library
Oracle Configurator
Oracle E-Business Suite
Oracle Payables
Oracle Iexpenses