PT-2006-1349 · Oracle · Oracle Application Server

·

CVE-2006-0275

·

Publicado

2006-01-18

·

Atualizado

2018-10-19

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Application Server version 9.0.4.2
Description The issue is related to directory traversal, allowing the reading of portions of arbitrary XML files via the customize parameter. This enables an attacker to access sensitive information.
Recommendations For Oracle Application Server version 9.0.4.2, consider restricting access to the customize parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the customize parameter in sensitive operations until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0275

Produtos afetados

Oracle Application Server