|
|
|
![]() |
Vulnerability Note VU#168873Oracle E-Business Suite Report Review Agent (RRA) allows arbitrary files to be retrieved with no authenticationOverviewA vulnerability in Oracle's E-Business Suite Report Review Agent (RRA) allows arbitrary files to be retrieved with no authentication.I. DescriptionA vulnerability exists in the Oracle E-Business Suite Report Review Agent (RRA). This vulnerability may allow a remote attacker to retrieve arbitrary information from Oracle Applications Concurrent Manager servers prior to authentication. For more information, please see the following documents:II. ImpactA remote attacker may be able to retrieve arbitrary information from Oracle Applications Concurrent Manager servers prior to authentication.III. SolutionApply a vendor supplied patch.Mitigation
References
This vulnerability was discovered by Stephen Kost of Integrigy Corporation. This document was written by Ian A Finlay.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||