PT-2015-2489 · Oracle · Oracle Application Object Library+1

Alexey Tyurin

+2

·

Published

2015-10-21

·

Updated

2018-12-10

·

CVE-2015-4886

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle E-Business Suite versions 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, 12.2.4
Description The issue affects the confidentiality and integrity of the system, potentially allowing remote attackers to impact it via unknown vectors related to Reports Security. There are claims that this issue might be related to an XML External Entity (XXE) vulnerability, which could enable remote attackers to read arbitrary files, cause a denial of service, or conduct SMB Relay attacks by crafting a DTD in an XML request involving the OA HTML/copxml servlet. Additionally, errors in the code of the Oracle Application Object Library component, specifically the Single Signon subcomponent, may allow a remote attacker to gain unauthorized access to read data.
Recommendations For Oracle E-Business Suite versions 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4, consider restricting access to the OA HTML/copxml servlet as a temporary workaround until a patch is available. As a mitigation measure, review and secure the configuration of the Single Signon subcomponent in the Oracle Application Object Library to minimize the risk of unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11854
CVE-2015-4886

Affected Products

Oracle Application Object Library
Oracle E-Business Suite