PT-2013-3177 · Oracle · Oracle Auto Service Request

Larry W. Cashdollar

·

Published

2013-03-18

·

Updated

2013-10-11

·

CVE-2013-1495

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Auto Service Request versions prior to 4.3.2
Description The issue allows local users to modify arbitrary files via a symlink attack on a predictable filename in /tmp. This is related to the asr in Oracle Auto Service Request in Oracle Support Tools.
Recommendations For versions prior to 4.3.2, update to version 4.3.2 or later to resolve the issue.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1495

Affected Products

Oracle Auto Service Request