PT-2016-4247 · Oracle · Oracle Enterprise Manager Grid Control

Rgod

·

Published

2016-01-21

·

Updated

2016-12-22

·

CVE-2016-0487

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Enterprise Manager Grid Control versions 12.4.0.2 through 12.5.0.2
Description The issue affects confidentiality and integrity, potentially allowing remote attackers to bypass authentication. It is related to the Test Manager for Web Apps component. There are claims that this could be a directory traversal vulnerability in the process method in the ActionServlet servlet, which might allow attackers to bypass authentication via directory traversal sequences following an unspecified URI string.
Recommendations For versions 12.4.0.2 and 12.5.0.2, consider restricting access to the ActionServlet servlet until a patch is available. As a temporary workaround, avoid using unspecified URI strings that could lead to directory traversal sequences in the affected component. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-0487
ZDI-16-033

Affected Products

Oracle Enterprise Manager Grid Control