Vulnerability Note VU#168873
Oracle E-Business Suite Report Review Agent (RRA) allows arbitrary files to be retrieved with no authentication
Overview
A vulnerability in Oracle's E-Business Suite Report Review Agent (RRA) allows arbitrary files to be retrieved with no authentication.
Description
A vulnerability exists in the Oracle E-Business Suite Report Review Agent (RRA). This vulnerability may allow a remote attacker to retrieve arbitrary information from Oracle Applications Concurrent Manager servers prior to authentication. For more information, please see the following documents: |
Impact
A remote attacker may be able to retrieve arbitrary information from Oracle Applications Concurrent Manager servers prior to authentication. |
Solution
Apply a vendor supplied patch. |
Mitigation
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Oracle Corporation | Affected | - | 14 Apr 2003 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.integrigy.com/info/Integrigy_OracleDB_Listener_Security.pdf
- http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf
- http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm
- http://securitytracker.com/alerts/2003/Apr/1006550.html
- http://www.oracle.com/applications/index.html
Credit
This vulnerability was discovered by Stephen Kost of Integrigy Corporation.
This document was written by Ian A Finlay.
Other Information
- CVE IDs: Unknown
- Date Public: 10 Apr 2003
- Date First Published: 14 Apr 2003
- Date Last Updated: 14 Apr 2003
- Severity Metric: 9.38
- Document Revision: 14
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.