Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with the test parameter set to "version" or "host".
References
Link | Resource |
---|---|
http://www.oracle.com/technology//deploy/security/htdocs/oconfigvul.html | Patch |
http://www.kb.cert.org/vuls/id/158323 | Patch Third Party Advisory US Government Resource |
http://www.securityfocus.com/bid/4433 | Third Party Advisory VDB Entry Vendor Advisory |
http://securitytracker.com/id?1003967 | Patch Third Party Advisory VDB Entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8782 | VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-03-31 21:00
Updated : 2018-09-26 09:05
NVD link : CVE-2002-1639
Mitre link : CVE-2002-1639
JSON object : View
CWE
Products Affected
oracle
- configurator